A potential security issue has been discovered by cybersecurity researchers that has the capability to affect more than one billion devices.
According to researchers at the cybersecurity firm Tarlogic,Busty Lifeguards (2010) a hidden command has been foundcoded into a bluetooth chip installed in devices around the world. This secret functionality can be weaponized by bad actors and, according to the researchers, used as an exploit into these devices.
Using these commands, hackers could impersonate a trusted device and then connect to smartphones, computers, and other devices in order to access information stored on them. Bad actors can continue to utilize their connection to the device to essentially spy on users.
The bluetooth chip is called ESP32 and is manufactured by the China-based company Espressif. According to researchers, the ESP32 is "a microcontroller that enables WiFi and Bluetooth connection." In 2023, Espressif reported that one billion units of its ESP32 chip had been sold globally. Millions of IoT devices like smart appliances utilize this particular ESP32 chip.
Tarlogic researchers say that this hidden command could be exploited, which would allow "hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls." Tarlogic says that these commands are not publicly documented by Espressif.
Researchers with Tarlogic developed a new Bluetooth driver tool in order to aid in Bluetooth-related security research, which enabled the security firm to discover a total of 29 hidden functionalities that could be exploited to impersonate known devices and access confidential information stored on a device.
According to Tarlogic, Espressif sells these bluetooth chips for roughly $2, which explains why so many devices utilize the component over higher costing options.
As BleepingComputerreports, the issue is being tracked as CVE-2025-27840.
Topics Bluetooth Cybersecurity
Dog Philosopher by Tom GauldPoets on Couches: Maya C. Popa by Maya C. PopaBetraying My Hometown by Yan LiankeHow to Draw the Coronavirus by Rebekah FrumkinWhat’s Inside That Giant Cross? by Steven E. JonesQuarantine Reads: The U.S.A. Trilogy by Jennifer SchafferFathers Sway above It All by Chelsea BiekerPoets on Couches: Cynthia Cruz by Cynthia CruzNot for the Fainthearted by Yiyun LiThe Land Empty, the World Empty by Jean GionoMy Lighthouses by Jazmina BarreraOut of the Cradle Endlessly Revising by Mark DotyPoets on Couches: Jake Skeets by The Paris ReviewPoets on Couches: Mary Szybist Reads Amy Woolard by Mary SzybistPoets on Couches: Shane McCrae Reads Lucie BrockOut of the Cradle Endlessly Revising by Mark DotyOur Motto by Maira KalmanWhy Certain Illnesses Remain Mysterious by Sarah RameyThe Black Gambling King of Chicago by Michael LaPointeNo Shelter by Lauren Sandler Meet the 35 New leaked photos show the full display of Samsung's Galaxy S8 Man opens bag of crisps to find only one inside. Yes, you read that right. Snap had a very special, very Snapchat lens for its IPO day that you can't get Firefighters rescue mischievous husky from roof twice in 1 hour Meet Orisa, the 24th 'Overwatch' hero Here's a device that make dads feel pregnant. Hey, why are you running away? Come baaaack! Now is the absolute worst time to buy an iPhone After epic drought, parts of California now have too much snow Spotify takes a cue from Tidal with hi Dev Patel has a girlfriend and everyone feels personally victimised Sorry Queen Elizabeth, this American claims to be your rightful heir Fed up Indian IT professionals want to be able to leave their jobs sooner This website is the Facebook for scientists, and it's growing with a $50 million raise 'The future that liberals want' is here, it's now and it's a meme Global warming made Australia's record The Oculus Rift and controllers dropped from $800 to $600 Dude applauded for buying elderly woman's groceries when her card declines Now you can order pizza with your shoes, because using your phone is so last year Netflix cuts out the chill with an integrated personal trainer
2.5044s , 10112.3046875 kb
Copyright © 2025 Powered by 【Busty Lifeguards (2010)】,Pursuit Information Network