Billions of devices imperiled by new clickless Bluetooth attack (ars technica)
Billions of devices imperiled by new clickless Bluetooth attack (ars technica)
Posted Sep 14, 2017 20:35 UTC (Thu) by excors (subscriber, #95769)In reply to: Billions of devices imperiled by new clickless Bluetooth attack (ars technica) by ssmith32
Parent article: Billions of devices imperiled by new clickless Bluetooth attack (ars technica)
Apparently the vulnerability is in native code that I expect gets compiled into somewhere like /system/lib/hw/bluetooth.default.so (if I'm reading the build scripts correctly), and gets loaded by the Java-based Bluetooth service (via JNI and some more interface layers) which is probably /system/app/Bluetooth.apk. Everything in /system is part of the firmware, and might be arbitrarily customised by the vendor (so even if Google could push security updates through the Play Store, they don't actually have the source code for those libraries (except on Nexus/Pixel devices)), so it can only be fixed in an OTA update.
If your phone is no longer getting OTA updates, throw it away and buy a new one.
