cross-posted from: https://sopuli.xyz/post/23587111

Archive: https://archive.is/2025.03.08-191658/https://www.bleepingcomputer.com/news/security/undocumented-backdoor-found-in-bluetooth-chip-used-by-a-billion-devices/

The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains an undocumented “backdoor” that could be leveraged for attacks.

The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence.

This was discovered by Spanish researchers Miguel Tarascó Acuña and Antonio Vázquez Blanco of Tarlogic Security, who presented their findings yesterday at RootedCON in Madrid.

  • just_another_person@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    Holeeeee shiiiiet. Big news. Surprised it took this long to find. Attack vectors are minimal, but still post, so if this isn’t addressed, it’s a clear sign it was a CCP sponsored job.

    • STOMPYI@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 months ago

      From what I’ve read you need a physical usb connection to access this loophole.