يحاول ذهب - حر

SECURITY BUG IN ESP CHIPS! What Is It? How To Handle It?

April 2025

|

Electronics For You

A hidden ESP32 feature could let attackers spoof devices, steal data, and install malware. With IoT security at stake, what does this mean for millions of connected devices?

- NIDHI AGARWAL AND ASHWINI KUMAR SINHA

SECURITY BUG IN ESP CHIPS! What Is It? How To Handle It?

Tarlogic Security has uncovered a hidden functionality in the ESP32, a widely used microcontroller that supports Wi-Fi and Bluetooth connectivity in millions of IoT devices. This undocumented feature, if exploited, could allow attackers to impersonate legitimate devices and install persistent malware on critical systems, including smartphones, computers, smart locks, and medical equipment. By bypassing standard code audit controls, malicious actors could potentially compromise sensitive devices at scale.

Cybercriminals could exploit these hidden commands to conduct impersonation or spoofing attacks. By creating fake Bluetooth devices that mimic legitimate ones, attackers could trick users into connecting, allowing them to intercept keystrokes, passwords, banking details, and personal messages. Beyond data theft, unauthorised remote control of devices is also a concern, with attackers potentially activating microphones or cameras unnoticed. The risk extends beyond smart-phones and laptops—digital door locks and medical devices could be compromised.

Espressif, the manufacturer of the ESP32, acknowledges the existence of these hidden commands but states that they are intended for debugging purposes. According to the company, these commands are part of the host controller interface (HCI) protocol used in Bluetooth communication and are typically used for internal testing. While debugging tools are standard in Bluetooth controllers, the presence of undocumented commands raises concerns about potential security risks and unauthorised access.

How to protect yourself from Bluetooth security risks

Backdoors and security flaws in Bluetooth devices can be exploited if not detected early. Conducting Bluetooth security audits is crucial to prevent potential threats.

  • Use security tools.

المزيد من القصص من Electronics For You

Electronics For You

Low-power, reliable transmitter chip

Researchers at MIT (United States) have developed a compact transmitter chip that reduces signal errors by a factor of four and extends battery life for IoT devices.

time to read

1 min

September 2025

Electronics For You

Electronics For You

Leading Suppliers of MICROSCOPES FOR OC OF ELECTRONICS

Who are India's Leading Suppliers of Microscopes for Quality Control of Electronics? Here is the list...

time to read

5 mins

September 2025

Electronics For You

Electronics For You

Compact swarm-level AI drones navigation using neural network

Researchers at Shanghai Jiao Tong University (Shanghai, China) have developed a compact AI navigation system for drones.

time to read

1 min

September 2025

Electronics For You

Electronics For You

ML-based wireless power transfer

Researchers at Chiba University (Chiba, Japan) have developed a machine learning-based method to design wireless power transfer (WPT) systems that stay efficient and stable across varying loads.

time to read

1 min

September 2025

Electronics For You

Wi-Fi that knows who you are

WhoFi, developed at La Sapienza University (Rome, Italy), is a Wi-Fi-based surveillance system that identifies individuals by how their bodies disrupt wireless signals; no cameras, contact, or consent is needed.

time to read

1 min

September 2025

Electronics For You

Electronics For You

3mm-thick holographic display that delivers lifelike 3D visuals

Stanford researchers (California) have unveiled a 3mm-thick holographic display that delivers lifelike 3D visuals using true holography, not stereoscopy.

time to read

1 min

September 2025

Electronics For You

Electronics For You

Smart Trolley Robot 'TROLL.E 1.0'

Robots now play a vital role across modern society, often described as human-like due to their growing presence in social and commercial environments.

time to read

3 mins

September 2025

Electronics For You

Compact metal-free thin-film supercapacitor delivers 200V

GDUT (Guangzhou, China )researchers have developed a metal-free thin-film supercapacitor (TFSC) stack that delivers 200V in just 3.8cm³.

time to read

1 min

September 2025

Electronics For You

Electronics For You

Al-powered self-driving lab tests materials 10x faster

Researchers at NC State (Raleigh, North Carolina) have developed an Al-powered self-driving lab that uses dynamicstate flow and real-time data to test materials 10x faster than traditional labs.

time to read

1 min

September 2025

Electronics For You

Electronics For You

Breakthrough in co-packaging photonic and electronic chips

The MIT (United States) FUTUR-IC team has developed a breakthrough chip packaging method that co-integrates electronics and photonics using passive alignment.

time to read

1 min

September 2025

Listen

Translate

Share

-
+

Change font size