- Feb 4, 2016
- 2,520
Over 20 million Amazon Echo and Google Home devices running on Android and Linux are vulnerable to attacks via the BlueBorne vulnerability, IoT cyber-security firm Armis announced today.
Both Amazon and Google have issued patches for the affected products, hence today's disclosure from Armis.
BlueBorne is a set of eight vulnerabilities in the Bluetooth implementations deployed on Android, iOS, Microsoft, and Linux. Affected OS makers and several IoT device makers issued updates in mid-September to address the flaws.
BlueBorne allows attackers to take over devices that have Bluetooth enabled and run malicious code on the underlying OS or firmware.
All sorts of devices most likely still vulnerable to BlueBorne
Back in September, Armis released an Android app to scan for BlueBorne vulnerable devices, and later released proof-of-concept exploit code on GitHub that security researchers could use to test if their personal or work devices are vulnerable to one of the eight BlueBorne flaws.
The easiest way to prevent BlueBorne attacks is to patch devices or disable the Bluetooth function.
A technical report on the BlueBorne flaws is available here. Below is a video describing the BlueBorne attack.
....
....
.........
..