
Black Hat Talk Reveals Six BLE Re-Pairing Vulnerabilities Affecting Major Vendors
The talk by Tomaso Saketi and Daniel Antoni at Black Hat covers vulnerabilities in Bluetooth Low Energy (BLE) re-pairing, a feature allowing paired devices to re-establish cryptographic keys. They identified six protocol-level flaws, including downgrade attacks and weak authentication, enabling impersonation (central/peripheral) and man-in-the-middle attacks. Their open-source "Blur" toolkit demonstrates these exploits, tested on 23 devices across 13 vendors (e.g., Apple, Google, Xiaomi), confirming widespread susceptibility. Mitigations proposed include implicit authentication and enforcing security level consistency, with partial fixes implemented by vendors like Google and Apple. The research was disclosed to the Bluetooth SIG and vendors, yielding a CVE (score 8.1) for the Nimble stack. The work builds on prior attacks (e.g., KNOB) and highlights gaps in BLE’s threat model.