Devices are at risk due to Bluetooth security vulnerability
By MYBRANDBOOK
A freshly highlighted vulnerability in Bluetooth 4.2 version has been detected, which could sanction an unauthenticated malicious attacker in the proximity of affected devices to intercept, monitor and manipulate the data they exchange.
The vulnerability which has been labeled as CVE-2018-5383 has been confirmed by Carnegie Mellon University's CERT. The loophole affects several Apple, Broadcom, Intel, and Qualcomm devices. Select Android handsets may also be affected. Microsoft has not been included in the list of affected companies, as the technology giant has reportedly not yet integrated the new Bluetooth version 4.2, the affected version, into its devices.
The vulnerability can be taken advantage of within Bluetooth's SSP (Secure Simple Pairing) and Low Energy Secure Connections. Favorably for macOS users, Apple released a patch before the public awareness of the vulnerability spread, as per news reports.
What is being done
Special Interest Group, the guardians of Bluetooth are now working on updating the specification of the framework and will require devices to validate any and all public keys received, as a component of the key-based security procedures.
Farrhad Acidwalla, media entrepreneur and founder of CYBERNETIV- Forward Thinking Enterprise Security & Research,comments, “While there are no confirmed mass reports of the newly discovered Bluetooth vulnerability being exploited on scale, this vulnerability could be taken of advantage of silently if consumers are not using the patched version over time. As Bluetooth is a globally used framework, it's a very attractive target for hackers and its scale and widespread makes it a very valuable vulnerability.”
Analysts are worried that a plethora of devices such as smart watches, wireless keyboards use Bluetooth at their very core. Hypothetically an attacker can sniff keystrokes from an affected keyboard, read banking notifications on a smartwatch and much more. As this is not the first time Bluetooth has been hit by a critical vulnerability it illustrates that security awareness amongst consumers is the need of the hour.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
DRUVA SOFTWARE PVT. LTD.
TP-LINK INDIA PVT. LTD.
QUICK HEAL TECHNOLOGIES PVT. LTD.
DELL TECHNOLOGIES INDIA PVT. LTD.
ICONS OF INDIA : SANDIP PATEL
Sandip Patel is the Managing Director for IBM India & South Asia regio...
Icons Of India : B.V.R. Subrahmanyam
A 1987 batch (Chhattisgarh cadre) Indian Administrative Service Office...
ICONS OF INDIA : RAJESH NAMBIAR
Rajesh leads the company’s India associates and enhances relationshi...
UIDAI - Unique Identification Authority of India
UIDAI and the Aadhaar system represent a significant milestone in Indi...
PFC - Power Finance Corporation Ltd
PFC is a leading financial institution in India specializing in power ...
NIC - National Informatics Centre
NIC serves as the primary IT solutions provider for the government of ...
Indian Tech Talent Excelling The Tech World - Vinod Dham, Founder & Executive Managing Partner, IndoUS Venture Partners
Vinod Dham, known as the “Father of the Pentium Chip,” has left an...
Indian Tech Talent Excelling The Tech World - ANJALI SUD, CEO – Tubi
Anjali Sud, the former CEO of Vimeo, now leads Tubi, Fox Corporation...
Indian Tech Talent Excelling The Tech World - George Kurian, CEO, Netapp
George Kurian, the CEO of global data storage and management services ...