https://www.armis.com/blueborne/
BlueBorne affects all Bluetooth enabled devices
They affect the Bluetooth implementations in Android, iOS, Microsoft, and Linux, impacting almost all Bluetooth device types, from smartphones to laptops, and from IoT devices to smart cars.
No user interaction is needed for an attacker to use the BleuBorne flaws, nor does the attacker need to pair with a target device.
Three of these eight security flaws are rated critical and according to researchers at Armis — the IoT security company that discovered BlueBorne — they allow attackers to take over devices and execute malicious code, or to run Man-in-the-Middle attacks and intercept Bluetooth communications.
Furthermore, the vulnerabilities can be concocted into a self-spreading BlueTooth worm that could wreak havoc inside a company's network or even across the world.
The vulnerabilities for Android are indexed as CVE-2017-0781, CVE-2017-0782, CVE-2017-0783, and CVE-2017-0785; the vulnerabilities for Linux are CVE-2017-1000251 and CVE-2017-1000250; the vulnerability for Windows is CVE-2017-8628; the designation for iOS vulnerability wasn't immediately available.
via https://www.bleepingcomputer.com/news/security/blueborne-vulnerabilitie…
Android demo video: https://www.youtube.com/watch?v=Az-l90RCns8
- Google – Contacted on April 19, 2017, after which details were shared. Released public security update and security bulletin on September 4th, 2017. Coordinated disclosure on September 12th, 2017.
- Microsoft – Contacted on April 19, 2017 after which details were shared. Public security updates on September 12, 2017. Coordinated disclosure on September 12th, 2017.
- Apple – Contacted on August 9, 2017. Apple had no vulnerability in its current versions.
- Samsung – Contact on three separate occasions in April, May, and June. No response was received back from any outreach.
- Linux – Contacted August 15 and 17, 2017. On September 5, 2017, we connected and provided the necessary information to the the Linux kernel security team and to the Linux distributions security contact list and conversations followed from there. Targeting updates for on or about September 12, 2017 for coordinated disclosure.