Author Topic: Undocumented chip commands found in billion-device bluetooth chips  (Read 1206 times)

0 Members and 1 Guest are viewing this topic.

Offline Kamaji

  • Hero Member
  • *****
  • Posts: 48,509
Undocumented chip commands found in billion-device bluetooth chips
« on: September 20, 2025, 03:54:52 pm »
Undocumented chip commands found in billion-device bluetooth chips

Story by Alexander Clark
September 20, 2025

Recent discoveries by cybersecurity researchers have unveiled undocumented commands hidden within Bluetooth chips, potentially impacting over a billion devices globally. These functionalities, previously unknown to both manufacturers and users, introduce significant security risks. As these findings come to light, industries are urgently working to address vulnerabilities and mitigate the potential for exploitation.

Cybersecurity experts recently made a startling discovery involving hidden commands embedded in Bluetooth chips, as reported by Bleeping Computer. This revelation emerged through meticulous reverse engineering and testing of the chips, which revealed previously concealed functionalities. These commands, which were not documented in any official manufacturer guides or documentation, could potentially be used for a range of purposes.

*  *  *

Source:  https://www.msn.com/en-us/news/technology/undocumented-chip-commands-found-in-billion-device-bluetooth-chips

Edit (updated source link)

Link:  https://www.msn.com/en-us/news/technology/undocumented-chip-commands-found-in-billion-device-bluetooth-chips/ar-AA1MY8SP
« Last Edit: September 20, 2025, 04:03:34 pm by Kamaji »
Nie mój cyrk, nie moje małpy

Online Smokin Joe

  • Hero Member
  • *****
  • Posts: 63,478
  • I was a "conspiracy theorist". Now I'm just right.
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #1 on: September 20, 2025, 04:00:56 pm »
Interesting...

Quote
"Whoops! This page doesn't exist or can't be found."
How God must weep at humans' folly! Stand fast! God knows what he is doing!
Seventeen Techniques for Truth Suppression

Of all tyrannies, a tyranny sincerely exercised for the good of its victims may be the most oppressive. It would be better to live under robber barons than under omnipotent moral busybodies. The robber baron's cruelty may sometimes sleep, his cupidity may at some point be satiated; but those who torment us for our own good will torment us without end for they do so with the approval of their own conscience.

C S Lewis


Offline Canuck Conservative

  • Hero Member
  • *****
  • Posts: 730
  • Gender: Male
  • Nature-loving Conservative!
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #3 on: September 20, 2025, 04:11:52 pm »
China again?
The elimination of the evil Soviet Union was one of the most glorious moments in Human History!!

Online Smokin Joe

  • Hero Member
  • *****
  • Posts: 63,478
  • I was a "conspiracy theorist". Now I'm just right.
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #4 on: September 20, 2025, 04:21:56 pm »
@Kamaji Thanks!

Quote
Consider a scenario where a hacker could access a smart home system via these undocumented commands, gaining control over locks, cameras, and alarms. Similarly, in a corporate setting, these vulnerabilities could lead to unauthorized access to sensitive corporate data, potentially resulting in financial loss and reputational damage. The stakes are even higher when considering national security, where critical infrastructure could be compromised.

No mention of the possibilities of potentially accessing or compromising automotive systems using Bluetooth back doors. What seemed like a conspiracy theory just edged closer to (or passed into) the realm of possibility.
How God must weep at humans' folly! Stand fast! God knows what he is doing!
Seventeen Techniques for Truth Suppression

Of all tyrannies, a tyranny sincerely exercised for the good of its victims may be the most oppressive. It would be better to live under robber barons than under omnipotent moral busybodies. The robber baron's cruelty may sometimes sleep, his cupidity may at some point be satiated; but those who torment us for our own good will torment us without end for they do so with the approval of their own conscience.

C S Lewis

Offline roamer_1

  • Hero Member
  • *****
  • Posts: 36,374
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #5 on: September 20, 2025, 04:23:28 pm »
meh. Prolly debug commands that require hands-on.  Bluetooth and Wifi are pretty tight.

Kinda like your windows box being pretty easy to exploit if I am sitting with it at my bench - but that really doesn't matter, because in-situ, it sits behind a router, so all those exploits are pretty much made moot.

Offline bigheadfred

  • Hero Member
  • *****
  • Posts: 15,704
  • Gender: Male
  • One day Closer
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #6 on: September 20, 2025, 04:28:05 pm »
Quote
The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains undocumented commands that could be leveraged for attacks.

From this link:

https://www.bleepingcomputer.com/news/security/undocumented-commands-found-in-bluetooth-chip-used-by-a-billion-devices/
She asked me name my foe then. I said the need within some men to fight and kill their brothers without thought of Love or God. Ken Hensley

Offline roamer_1

  • Hero Member
  • *****
  • Posts: 36,374
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #7 on: September 20, 2025, 04:42:03 pm »
Yeah. Debug commands.

Ya want to know the REAL danger?
Look how they fixed it.

They are going to update the chip to take the commands out.
The real danger is not what the chip may or may not have onboard for commands. The real danger is that any chip can be updated at will.

Whoever can control that update channel, either for real or by spoof, can pump the commands they want into that chip at any time.

Online Bigun

  • Hero Member
  • *****
  • Posts: 35,753
  • Gender: Male
  • Resistance to Tyrants is Obedience to God
    • The FairTax Plan
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #8 on: September 20, 2025, 05:55:48 pm »
I wonder how much shit like this could be found in our electronic voting devices if anyone cared to look?
"I wish it need not have happened in my time," said Frodo.

"So do I," said Gandalf, "and so do all who live to see such times. But that is not for them to decide. All we have to decide is what to do with the time that is given us."
- J. R. R. Tolkien

Online Cyber Liberty

  • Coffee! Donuts! Kittens!
  • Administrator
  • ******
  • Posts: 63,434
  • Gender: Male
  • 🌵🌵🌵
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #9 on: September 20, 2025, 06:05:04 pm »
Yeah. Debug commands.

Ya want to know the REAL danger?
Look how they fixed it.

They are going to update the chip to take the commands out.
The real danger is not what the chip may or may not have onboard for commands. The real danger is that any chip can be updated at will.

Whoever can control that update channel, either for real or by spoof, can pump the commands they want into that chip at any time.

I noticed that in the article too.  What's keeping someone from adding nefarious commands in the normal procedure of Firmware Updates?  I get those a few times a year on this machine.
For unvaccinated, we are looking at a winter of severe illness and death — if you’re unvaccinated — for themselves, their families, and the hospitals they’ll soon overwhelm. Sloe Joe Biteme 12/16
I will NOT comply.
 
Castillo del Cyber Autonomous Zone ~~~~~>                          :dontfeed:

Online Bigun

  • Hero Member
  • *****
  • Posts: 35,753
  • Gender: Male
  • Resistance to Tyrants is Obedience to God
    • The FairTax Plan
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #10 on: September 20, 2025, 06:12:39 pm »
I noticed that in the article too.  What's keeping someone from adding nefarious commands in the normal procedure of Firmware Updates?  I get those a few times a year on this machine.

What's to keep something from being included on a chip entirely undocumented? something like a modem that broadcasts and receives on a propriatory frequency for instance.
« Last Edit: September 20, 2025, 06:17:42 pm by Bigun »
"I wish it need not have happened in my time," said Frodo.

"So do I," said Gandalf, "and so do all who live to see such times. But that is not for them to decide. All we have to decide is what to do with the time that is given us."
- J. R. R. Tolkien

Offline roamer_1

  • Hero Member
  • *****
  • Posts: 36,374
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #11 on: September 20, 2025, 06:37:21 pm »
I noticed that in the article too.  What's keeping someone from adding nefarious commands in the normal procedure of Firmware Updates?  I get those a few times a year on this machine.


That's the thing. Yeah it's all encrypted, but at a chip level, that cannot be very complicated.

There is also necessarily, a single point of contact - No matter how obfuscated, that point of contact must be defined and maintained.

So crack the encryption, and sniff the transmission... spoof all that, and you're talking to the chip instead.

Now, that's a pretty simple understanding that really ain't all that simple... firmware usually is handled by the OS, but that really makes it easier, because the OS has its flaws too... and so it goes.  :shrug:

Offline roamer_1

  • Hero Member
  • *****
  • Posts: 36,374
Re: Undocumented chip commands found in billion-device bluetooth chips
« Reply #12 on: September 20, 2025, 06:40:42 pm »
What's to keep something from being included on a chip entirely undocumented? something like a modem that broadcasts and receives on a propriatory frequency for instance.

That really ain't that likely. At the EEPROM level, a chip's functions are relatively easy to deconstruct. That those functions may change at any given time... well, that's another thing altogether. You can't continue to keep watch very easily.