Bluetooth for Windows Remote Audio Eavesdropping

This setting allows anyone to remotely inject audio into a victim’s PCspeakers, as well as remotely monitor audio via the microphone.

This is one of the scariest hacks I’ve seen lately. As indicated above, it allows you to record or play audio remotely on a victim’s machine! This vulnerability applies to the Widcomm Windows bluetooth drivers which do not require authentication in order to connect to the Audio Gateway.
More information, including remediation steps, can be found here.
What would people hear you saying at your desk? (I mostly curse certain vendors web browsers, occasionally burp, and say “wow, that’s cool” a lot). Now, as far as being able to play audio on a remote machine I could have so much fun with that one. Just think, the “The Italian Christmas Donkey” song playing over and over and over and over and over……
Full Advisory

Paul Asadoorian

Paul Asadoorian is currently the Principal Security Evangelist for Eclypsium, focused on firmware and supply chain security awareness. Paul’s passion for firmware security extends back many years to the WRT54G hacking days and reverse engineering firmware on IoT devices for fun. Paul and his long-time podcast co-host Larry Pesce co-authored the book “WRTG54G Ultimate Hacking” in 2007, which fueled the firmware hacking fire even more. Paul has worked in technology and information security for over 20 years, holding various security and engineering roles in a lottery company, university, ISP, independent penetration tester, and security product companies such as Tenable. In 2005 Paul founded Security Weekly, a weekly podcast dedicated to hacking and information security. In 2020 Security Weekly was acquired by the Cyberrisk Alliance. Paul is still the host of one of the longest-running security podcasts, Paul’s Security Weekly, he enjoys coding in Python & telling everyone he uses Linux.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.