|
|
|
|
|
by vlovich123
466 days ago
|
|
You’ve misread then: > Armed with this new tool, which enables raw access to Bluetooth traffic, Targolic discovered hidden vendor-specific commands (Opcode 0x3F) in the ESP32 Bluetooth firmware that allow low-level control over Bluetooth functions. The exploit happens over bluetooth. They used a USBC driver to explore the potential attack surface. Shit like this is what happens when you don’t have good separation between functionality you give QA for production firmware & commands for factory firmware bringup. Almost certainly this is because the vendor used the same image for factory bringup & shipping to end users. |
|