this post was submitted on 09 Mar 2025
45 points (85.7% liked)

homeassistant

13239 readers
288 users here now

Home Assistant is open source home automation that puts local control and privacy first. Powered by a worldwide community of tinkerers and DIY enthusiasts. Perfect to run on a Raspberry Pi or a local server. Available for free at home-assistant.io

founded 2 years ago
MODERATORS
 

cross-posted from: https://sopuli.xyz/post/23587111

Archive: https://archive.is/2025.03.08-191658/https://www.bleepingcomputer.com/news/security/undocumented-backdoor-found-in-bluetooth-chip-used-by-a-billion-devices/

The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains an undocumented "backdoor" that could be leveraged for attacks.

The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence.

This was discovered by Spanish researchers Miguel Tarascó Acuña and Antonio Vázquez Blanco of Tarlogic Security, who presented their findings yesterday at RootedCON in Madrid.

you are viewing a single comment's thread
view the rest of the comments
[–] STOMPYI 12 points 3 days ago (1 children)

From what I've read you need a physical usb connection to access this loophole.

[–] snausagesinablanket 5 points 3 days ago (3 children)

Better call in Zero_Cool and Acid_Burn.

[–] [email protected] 6 points 2 days ago

I don't appreciate you referencing that movie in an unserious tone.

[–] SidewaysHighways 3 points 2 days ago

hack the planet!

[–] [email protected] 3 points 2 days ago

Wasn’t it Crash Override and Acid Burn?