A potential security issue has been discovered by cybersecurity researchers that has the capability to affect more than one billion devices.
According to researchers at the cybersecurity firm Tarlogic,giddens, a. the transformation of intimacy: sexuality, love, and eroticism in modern societies a hidden command has been foundcoded into a bluetooth chip installed in devices around the world. This secret functionality can be weaponized by bad actors and, according to the researchers, used as an exploit into these devices.
Using these commands, hackers could impersonate a trusted device and then connect to smartphones, computers, and other devices in order to access information stored on them. Bad actors can continue to utilize their connection to the device to essentially spy on users.
The bluetooth chip is called ESP32 and is manufactured by the China-based company Espressif. According to researchers, the ESP32 is "a microcontroller that enables WiFi and Bluetooth connection." In 2023, Espressif reported that one billion units of its ESP32 chip had been sold globally. Millions of IoT devices like smart appliances utilize this particular ESP32 chip.
Tarlogic researchers say that this hidden command could be exploited, which would allow "hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls." Tarlogic says that these commands are not publicly documented by Espressif.
Researchers with Tarlogic developed a new Bluetooth driver tool in order to aid in Bluetooth-related security research, which enabled the security firm to discover a total of 29 hidden functionalities that could be exploited to impersonate known devices and access confidential information stored on a device.
According to Tarlogic, Espressif sells these bluetooth chips for roughly $2, which explains why so many devices utilize the component over higher costing options.
As BleepingComputerreports, the issue is being tracked as CVE-2025-27840.
Topics Bluetooth Cybersecurity
Well Preserved by Ian VolnerLego free Paddle: How to get free Lego for Father's DayWords We Don't Say; The Tao of Travel by Lorin SteinFrancine Prose on 'My New American Life' by Thessaly La ForceThe Punk Ballerina by Miranda PopkeyInto the Deep by Lori NixSteak and Poetry from the Rooftops by Emily WittA Week in Culture: Joe Ollmann, Cartoonist by Joe OllmannHempelian Moods; My Friend’s Fancy Book Deal by Lorin SteinPart 3: To the Mandarin Oriental by Clancy MartinA Week in Culture: Chris Weitz, Director by Chris WeitzRob Brydon and Steve Coogan on The TripThe Punk Ballerina by Miranda PopkeyJoe Dunthorne on ‘Submarine’ by Thomas BunsteadA Week in Culture: Matthew Specktor, Writer and Editor by Matthew SpecktorThe Summer Issue: Redefining the Beach Read Since 1953 by Sadie SteinVladimir Nabokov and the Art of the SelfThe Summer Issue: Redefining the Beach Read Since 1953 by Sadie SteinPoem: Pomme by Rachel Jamison WebsterHempelian Moods; My Friend’s Fancy Book Deal by Lorin Stein Food is actually being served on iPads and it's my nightmare Dramatic astronaut photos show extreme wildfires burning in California Why you should be skeptical of tools to fight smartphone addiction 23andMe has pledged to follow new guidelines on how they handle people's DNA NSYNC's Lance Bass almost bought 'The Brady Bunch' house J.K. Rowling pens passionate defense of Europe ahead of referendum LeBron avoids subtlety by throwing shade with a new post Woman finds 16 The perfect time to watch HBO's 'Succession' is right now How to water bottle flip your way into a new job You can now pre Driver safety is 'all talk' with this AI real MoviePass is still standing and the company's statement is wild Google Maps adds a 3D Globe Mode Here's how Poor Cat Designs keeps a personal touch in the age of AI Samsung's Galaxy Note 9 is rumored to cost around $1,000 Running down memory lane with Trump's just The Queen cordially tweeted her thanks to everyone who wished her a happy birthday 2 weird dogs desperately try to lick a slug from the wrong side of a glass door Apple is killing its App Store affiliate program
2.6448s , 8262.6875 kb
Copyright © 2025 Powered by 【giddens, a. the transformation of intimacy: sexuality, love, and eroticism in modern societies】,Feast Information Network