A potential security issue has been discovered by cybersecurity researchers that has the capability to affect more than one billion devices.
According to researchers at the cybersecurity firm Tarlogic80p Archives a hidden command has been foundcoded into a bluetooth chip installed in devices around the world. This secret functionality can be weaponized by bad actors and, according to the researchers, used as an exploit into these devices.
Using these commands, hackers could impersonate a trusted device and then connect to smartphones, computers, and other devices in order to access information stored on them. Bad actors can continue to utilize their connection to the device to essentially spy on users.
The bluetooth chip is called ESP32 and is manufactured by the China-based company Espressif. According to researchers, the ESP32 is "a microcontroller that enables WiFi and Bluetooth connection." In 2023, Espressif reported that one billion units of its ESP32 chip had been sold globally. Millions of IoT devices like smart appliances utilize this particular ESP32 chip.
Tarlogic researchers say that this hidden command could be exploited, which would allow "hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls." Tarlogic says that these commands are not publicly documented by Espressif.
Researchers with Tarlogic developed a new Bluetooth driver tool in order to aid in Bluetooth-related security research, which enabled the security firm to discover a total of 29 hidden functionalities that could be exploited to impersonate known devices and access confidential information stored on a device.
According to Tarlogic, Espressif sells these bluetooth chips for roughly $2, which explains why so many devices utilize the component over higher costing options.
As BleepingComputerreports, the issue is being tracked as CVE-2025-27840.
Topics Bluetooth Cybersecurity
Called Back by Casey N. CepShopping for Groceries with the Romantic Poets by Jason Novak14 TikTok accounts to follow for fun STEM lessonsBluesky let users register usernames with racial slurs. The community feels betrayed.An unopened iPhone just sold for more than $190,000 at auction'Quordle' today: See each 'Quordle' answer and hints for July 17O Canada by Sadie SteinSnail’s Pace by Sadie SteinBeat It by Sadie SteinSurprised by Joy by Sadie SteinThe Paris Review and WNYC, a Perfect Match by Sadie Stein'Quordle' today: See each 'Quordle' answer and hints for July 18Claire Vaye Watkins Wins Dylan Thomas Prize by Sadie SteinNovena by Sadie SteinNotes from a Bookshop: Early Autumn, or Winter’s Coming by Kelly McMastersVile BodiesApple's M3 Macs likely already on the way later this yearDoes 'Barbie' have a postOpenAI announces $5 million partnership to support local newsOr, the Modern Prometheus by Sadie Stein Scams to look out for in 2025 Nvidia's new PC gaming app is making games run worse, but there's a quick fix Best Echo Spot deal: Save $35 at Amazon Clemson vs. Texas football livestreams: kickoff time, streaming deals, and more Arkadium mini crossword answers for December 18 Arkadium mini crossword answers for December 17 iOS 18.3 release date: When you can try this new, fun feature Polyamorous influencer breakups: What happens when hypervisible relationships end Best Bose QuietComfort Ultra earbuds deal: Save $70 at Amazon Best Amazon deal: Shop select fitness and outdoor gear and save $25 when you spend $200 Apple's Home app could get robot vacuum support in iOS 18.3 Best power bank deal: Save 40% on Anker Prime portable charger Tablet deals: Get up to 46% off on tablets from Amazon, Apple, and Samsung NYT Connections Sports Edition hints and answers for December 19: Tips to solve Connections #87 How to cope with heartbreak during the holidays Chicago Bulls vs. Boston Celtics 2024 livestream: Watch NBA online Can you ever cut all ties after a breakup in the digital age? Best HP laptop deal: Save $600 on OmniBook Ultra 14 Pornhub will block Florida staring January 1 Apple reportedly cancels plans for iPhone subscription service