Bluetooth hijack bug among 25 Android flaws patched in February

Attackers could have exploited the flaw on older systems to execute arbitrary code on target devices

Google has issued a collection of security updates to its Android mobile OS including patching a critically severe Bluetooth hijacking vulnerability that was first flagged to the developer in November last year.

The flaw, dubbed CVE-2020-0022, could have allowed an attacker, within range of Bluetooth signal, to execute arbitrary code with privileges of the Bluetooth daemon so long as Bluetooth is enabled on a vulnerable device. 

This form of attack could have been executed by knowing just the Bluetooth MAC address of the target device, which could have, for some devices, been derived from the Wi-Fi MAC address, according to researchers with security firm ERNW

The flaw, which was first flagged on 3 November 2019, affects older versions of Android, although it’s not exploitable for technical reasons on Android 10, and results instead in a crash of the Bluetooth daemon.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

“On Android 8.0 to 9.0, a remote attacker within proximity can silently execute arbitrary code with the privileges of the Bluetooth daemon as long as Bluetooth is enabled,” the ERNW researchers said. 

“No user interaction is required and only the Bluetooth MAC address of the target devices has to be known. For some devices, the Bluetooth MAC address can be deduced from the WiFi MAC address. This vulnerability can lead to theft of personal data and could potentially be used to spread malware (Short-Distance Worm).”

Related Resource

Report: The State of Software Security

This annual report explores important trends in software security

Download now

The collection of security updates also includes two dozen further patches for Android bugs ranging in severity from moderate to critical, although the vast majority of flaws are rated as being ‘highly’ severe.

There are several elevation of privilege bugs in the batch, as well as a moderate denial of service bug and a critically-rated information disclosure vulnerability.

Users have been advised to update their devices as soon as possible to receive the latest security updates, although there are a handful of mitigations users can employ. 

The researchers who initially discovered the bug have urged all Android users to enable Bluetooth if only strictly necessary, and to keep their devices non-discoverable.

Advertisement - Article continues below

They have pledged to release the technical report on the vulnerability, as well as the proof of concept code, one they’re confident that patches have reached end users.

While Bluetooth vulnerabilities in mobile phones are unusual, researchers found a flaw in Google’s Titan security keys last year that could allow attackers to bypass encryption and hijack user accounts.

Discovered in May 2019, the flaw involved a misconfigured Bluetooth pairing protocol with the FIDO key, with non-Bluetooth devices unaffected.

In August, meanwhile, researchers discovered a flaw in Bluetooth authentication protocols that allowed hackers to listen in on conversations held over Bluetooth devices, or even change the contents of file transfers.

The attack, dubbed Key Negotiation of Bluetooth (KNOB), worked by forcing participants in a Bluetooth handshake to use an encryption key with just one byte of entropy, allowing an attacker to brute-force the key. 

Featured Resources

Digital Risk Report 2020

A global view into the impact of digital transformation on risk and security management

Download now

6 ways your business could suffer if you don’t backup Office 365

Office 365 makes it easy to lose valuable data regularly, unpredictably, unintentionally, and for good

Download now

Get the best out of your workforce

7 steps to unleashing their true potential with robotic process automation

Download now

8 digital best practices for IT professionals

Don't leave anything to chance when going digital

Download now
Advertisement

Most Popular

Visit/mobile/28299/how-to-use-chromecast-without-wi-fi
Mobile

How to use Chromecast without Wi-Fi

5 Feb 2020
Visit/operating-systems/27717/how-to-fix-a-stuck-windows-10-update
operating systems

How to fix a stuck Windows 10 update

12 Feb 2020
Visit/security/34616/the-top-ten-password-cracking-techniques-used-by-hackers
Security

The top ten password-cracking techniques used by hackers

10 Feb 2020
Visit/software/linux/354831/microsoft-to-add-defender-antivirus-software-to-linux-ios-and-android
Linux

Microsoft to add Defender antivirus software to Linux, iOS and Android

21 Feb 2020