• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 

2

Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics

3

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'

1

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 

2

Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics

3

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
TechCybersecurity

Hackers Can Take Over Billions of Android and Linux Devices via Bluetooth

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
September 12, 2017, 9:00 AM ET

Security researchers have discovered a set of severe vulnerabilities affecting devices that connect via Bluetooth.

The eight security holes—three of which are considered “critical”—allow attackers to take control of Bluetooth-enabled devices, execute code remotely, or intercept traffic between laptops, phones, smart TVs, watches, and other “Internet of things” devices. The vulnerabilities affect unpatched versions of Google Android, Microsoft Windows, Linux operating system, and Apple iOS.

Researchers have dubbed the attack that takes advantage of these code flaws “BlueBorne” because it is airborne and spreads via Bluetooth. The researchers envision a worst-case scenario in which a major ransomware attack, like WannaCry from earlier this year, spreads like wildfire, jumping from phone to phone and “bricking” people’s devices.

This attack would not require people to click on links, download malicious files, or “pair” devices to work; it would merely require people to have Bluetooth enabled.

More information on the attack can be found below.

“No security mechanism is there to block incoming Bluetooth connections, so an attacker can bypass all of them completely,” says Ben Seri, head of research at Armis Security, the two-year-old cybersecurity startup that found the security holes.

“Imagine WannaCry Blue,” adds Michael Parker, Armis’ head of marketing.

The researchers say they reported the vulnerabilities to Apple, Google, and Microsoft in April and to Linux in August. They held off on publishing their work in order to coordinate disclosure with the affected companies. (For more on coordinated vulnerability disclosure, read this recent Fortune feature.)

Most of the tech companies and organizations have addressed the issues—although there are exceptions.

Apple said it had already fixed the issue with its release of iOS 10 a year ago; however, people running earlier versions of the software are vulnerable. Microsoft said it released a patch during a regularly scheduled Patch Tuesday in July.

“Customers who have Windows Update enabled and applied the security updates, are protected automatically,” a Microsoft (MSFT) spokesperson tells Fortune. “We updated to protect customers as soon as possible, but as a responsible industry partner, we withheld disclosure until other vendors could develop and release updates.”

The researchers said they expect Linux, which is an open source project managed by a community of volunteers, to release a fix soon. (The Linux team did not immediately respond to Fortune’s inquiry.)

Get Data Sheet, Fortune’s technology newsletter.

Google represents a trickier situation. The tech giant’s Android ecosystem is fragmented across a wide variety of partners, such as phone manufacturers and mobile carriers, who are responsible for distributing patches developed by Google.

“We have released security updates for these issues, and will continue working with other affected platforms across the industry to develop protections that help keep users safe,” says Aaron Stein, a Google spokesperson. He notes that Google’s proprietary Pixel and Nexus phones would be updated automatically, and that partners—manufacturers like Samsung, HTC, and Sony, as well as wireless carriers like Verizon, AT&T, and T-Mobile—have had the patch for about a month.

Android users who wish to know whether they are vulnerable can download an app Armis developed to provide a check. When patches are available, consumers should update their devices to the latest available operating systems in order to protect themselves from the attacks.

In the interim, people can also disable Bluetooth until the proper patches are available and applied. More information about the Android, Windows, and Linux attacks can be found in the videos below.

“Bluetooth is complicated. Too complicated,” the researchers write in their whitepaper discussing the attacks. “[A]s the Bluetooth stack is such an immense piece of code, the work we are presenting might be only the tip of the iceberg.”

“These silent attacks are invisible to traditional security controls and procedures. Companies don’t monitor these types of device-to-device connections in their environment, so they can’t see these attacks or stop them,” said Yevgeny Dibrov, CEO of Armis, in a statement. Armis’ 40-person team is headquartered in Palo Alto, Calif. and Tel Aviv, and has raised $17 million in venture capital from investors such as Sequoia Capital and Tenaya Capital.

The group that oversees Bluetooth technology, called the Bluetooth Special Interest Group, estimates that there are more than 8 billion Bluetooth devices on the market today.

As with any technology, devices running older versions of software tend to have vulnerabilities. It’s generally a wise practice to keep the software on your devices up to date.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Samuel Corum/Getty Images
Big TechSpaceX
Elon Musk’s proposed pay package in SpaceX’s IPO filing reveals what the company actually is: a $1 trillion monster built to colonize Mars
By Eva RoytburgMay 20, 2026
3 hours ago
elon
SuccessIPOs
SpaceX IPO targets $28.5 trillion total addressable market, mission to ‘make life multiplanetary’ and understand ‘true nature of the universe’
By Nick LichtenbergMay 20, 2026
5 hours ago
Jensen Huang, chief executive officer of Nvidia
AINvidia
Nvidia tells skeptical investors that AI is ready to go mainstream
By Ian King and BloombergMay 20, 2026
5 hours ago
SpaceX finally files IPO prospectus, reveals revenue is up–but losses are too
Big TechSpaceX
SpaceX finally files IPO prospectus, reveals revenue is up–but losses are too
By Allie Garfinkle and Alexei OreskovicMay 20, 2026
5 hours ago
Elon Musk sits with his fists together, looking up.
Commentaryspace
SpaceX will be worth trillions, but the space station that made it possible is worth even more — if we don’t squander it
By Tejpaul BhatiaMay 20, 2026
5 hours ago
Antler CEO Magnus Grimeland says Silicon Valley doesn’t have a monopoly on tech: ‘People can innovate from almost anywhere’
AsiaAsia Agenda
Antler CEO Magnus Grimeland says Silicon Valley doesn’t have a monopoly on tech: ‘People can innovate from almost anywhere’
By Angelica AngMay 20, 2026
5 hours ago

Most Popular

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
Workplace Culture
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
By Preston ForeMay 19, 2026
1 day ago
Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
Future of Work
Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
By Mike Householder and The Associated PressMay 17, 2026
3 days ago
Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
Success
Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
By Preston ForeMay 20, 2026
12 hours ago
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
8 days ago
Spirit Airlines apologizes to all the Americans who can't afford any summer vacation flights as it shuts down
Travel & Leisure
Spirit Airlines apologizes to all the Americans who can't afford any summer vacation flights as it shuts down
By Rio Yamat and The Associated PressMay 18, 2026
3 days ago
Dr. Bernice King on why companies that walked back DEI were never truly committed: 'If you retreat that quick…that reveals who you really are'
Workplace Culture
Dr. Bernice King on why companies that walked back DEI were never truly committed: 'If you retreat that quick…that reveals who you really are'
By Preston ForeMay 19, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.