Bluetooth vulnerability allows unauthorized user to record and play audio on Bluetooth speakers

This critical security issue allows third party user to record audio from Bluetooth speaker with built-in microphone in vicinity, even when it is already paired and connected with another device. This can result in eavesdropping on private conversations using turned on Bluetooth speaker or a headset. This security problem was found and presented by Tarlogic

Mobile Hacker
Bluetooth vulnerability allows unauthorized user to record and play audio on Bluetooth speakers

This critical security issue allows third party user to record audio from Bluetooth speaker with built-in microphone in vicinity, even when it is already paired and connected with another device. This can result in eavesdropping on private conversations using turned on Bluetooth speaker or a headset. This security problem was found and presented by Tarlogic

Mobile Hacker

Bluetooth is a hole, and the time has come to plug it. Our colleague @antonvblanco has just made this very clear at the @rootedcon Panama.

#BSAM #BlueSpy #BluetoothWallOfShame #STICPANAMÁ

Bluetooth Eavesdropping Threat Exposed: New "BlueSpy" Exploit Targets Popular Headsets

BlueSpy exploit highlights how the widespread use of insecure pairing methods in consumer Bluetooth headsets poses a significant privacy risk

Cybersecurity News
#BlueSpy is a proof of concept that allows exploiting vulnerabilities in Bluetooth headsets and the spying on conversations. Jesús Mª Gómez, from the @Tarlogic Innovation team, explains how to identify vulnerabilities using #BSAM and how BlueSpy works.
https://www.tarlogic.com/blog/bluespy-spying-on-bluetooth-conversations/
BlueSpy - Spying on Bluetooth conversations

BlueSpy is a proof of concept for exploiting vulnerabilities in Bluetooth headsets and eavesdropping on private conversations

Tarlogic Security
🚨 #BlueSpy is now available on our GitHub. This proof-of-concept allows you to listen in on conversations from Bluetooth headsets without your users' knowledge. We have already alerted manufacturers whose devices have some vulnerabilities.
https://github.com/TarlogicSecurity/BlueSpy
GitHub - TarlogicSecurity/BlueSpy: PoC to record audio from a Bluetooth device

PoC to record audio from a Bluetooth device. Contribute to TarlogicSecurity/BlueSpy development by creating an account on GitHub.

GitHub