started · updated
Bluetooth security risks increase with constant connectivity
Leaving Bluetooth enabled on smartphones and connected devices increases the window of exposure to various cyberattacks. Security vulnerabilities in Bluetooth hardware and software can allow attackers to access personal information, track locations, or intercept communications.
Specific documented risks include vulnerabilities in Fitbit devices that could allow users to be tracked via open algorithms. Additionally, research by Insinuator identified flaws in Airoha chips, which are widely used in audio accessories. These flaws could enable an attacker within radio range to listen to conversations or steal data such as contact lists and call histories.
To mitigate these risks, experts recommend disabling Bluetooth when not in use and using ‘hidden’ mode rather than ‘discoverable’ mode. Other security practices include disconnecting phones from rental car systems before returning them, erasing personal data before selling a vehicle, and disabling wireless Android Auto to limit the combination of Bluetooth and Wi-Fi exposure.
Entities
Airoha · Fitbit · Insinuator