A potential security issue has been discovered by cybersecurity researchers that has the capability to affect more than one billion devices.
According to researchers at the cybersecurity firm Tarlogic,Mika Muroi Archives a hidden command has been foundcoded into a bluetooth chip installed in devices around the world. This secret functionality can be weaponized by bad actors and, according to the researchers, used as an exploit into these devices.
Using these commands, hackers could impersonate a trusted device and then connect to smartphones, computers, and other devices in order to access information stored on them. Bad actors can continue to utilize their connection to the device to essentially spy on users.
The bluetooth chip is called ESP32 and is manufactured by the China-based company Espressif. According to researchers, the ESP32 is "a microcontroller that enables WiFi and Bluetooth connection." In 2023, Espressif reported that one billion units of its ESP32 chip had been sold globally. Millions of IoT devices like smart appliances utilize this particular ESP32 chip.
Tarlogic researchers say that this hidden command could be exploited, which would allow "hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls." Tarlogic says that these commands are not publicly documented by Espressif.
Researchers with Tarlogic developed a new Bluetooth driver tool in order to aid in Bluetooth-related security research, which enabled the security firm to discover a total of 29 hidden functionalities that could be exploited to impersonate known devices and access confidential information stored on a device.
According to Tarlogic, Espressif sells these bluetooth chips for roughly $2, which explains why so many devices utilize the component over higher costing options.
As BleepingComputerreports, the issue is being tracked as CVE-2025-27840.
Topics Bluetooth Cybersecurity
The Etymology of “Okay”5 Forgotten Christmas Ghost Stories100 Years of Design on the LandOn Set with Matthew BarneyJane Freilicher, 1924–2014How Should We Mourn the Death of Local Institutions?How Horror Games Like “The Evil Within” Violate Our TrustAt MoMA PS1, Bob and Roberta Smith Offer Art AmnestyThe Pigshit at the End of the Rainbow: Remembering Robert StoneStaff Picks: Devin Johnston, Darrel Rees, and MoreOn Set with Matthew BarneyThe Wonders of IndustrialThe Lost Recordings of a Phantom MusicianThe Etymology of “Okay”The Pigshit at the End of the Rainbow: Remembering Robert StoneEamonn Doyle, iStanisław Barańczak’s “This Is Not a Conversation for the Telephone” by Dan PiepenbringAn Absolute Truth: On Writing a Life of ColtraneThe Best Cauldons in Children’s Books: A Forgotten ContenderCan You Read About New York in the 1920s Without Nostalgia? Redeeming Greek Speak: An Interview with Ben Nugent The Game of the Name: A Really Difficult Puzzle Notes on Orlando Bloom’s Penis Meta's Horizon Worlds faces tough Twitter criticism The Strange Allure of Watching “How It’s Made” The 9 best and funniest tweets of the week Tinder for readers: Klerb is the new social app based on books you love Michael Kidner’s “Visual Anarchy” The Game of the Name: The Answers Microsoft's AI Copilot can take meetings for you now How to watch Indiana vs. Rutgers football without cable: kickoff time, streaming deals, and more It Is Very, Very, Very Hard to Adapt a Philip Roth Novel The Landlord from Ioway: James Alan McPherson, 1943–2016 White House official Twitter calls out student debt forgiveness objectors over their PPP loans Staff Picks: Wharton, Fermor, and Faking Your Own Death Summer with a Thousand Julys Vik Muniz Pays Attention to the Other Side of the Painting A Fan’s Notes: How Sports Taught Me to Think Controversial influencer Andrew Tate banned from Facebook and Instagram Mourning the Unrealized Promise of Aerosolized Foods
2.1568s , 10110.7421875 kb
Copyright © 2025 Powered by 【Mika Muroi Archives】,Miracle Information Network