Security

A Set of Bluetooth Flaws Named “SweynTooth” Affects Hundreds of Devices (Updated)

Written by Bill Toulas
Last updated September 23, 2021

Researchers from the Singapore University of Technology and Design have discovered a collection of vulnerabilities that underpin Bluetooth Low Energy (BLE) systems. Calling the set of the 11 flaws “SweynTooth”, they warn about the extent of its affection as it is to be found across various BLE SDKs used by at least six SoC (system on a chip) vendors. This means that the list of the devices that are vulnerable to SweynTooth contains at least five hundred entries. The flaws with their identifiers are given below:

blue_flaw

Sequential ATT Deadlock Diagram, Source: ASSET Research Group

The above enables an attacker to crash a device by triggering a series of faults via memory corruption, create deadlocks in the SDK firmware which would force the device to endlessly reboot, and bypass security measures. This last one is the most critical of all, as an attacker in Bluetooth range could pair with a device without authorization, and without the owner realizing it. The vendors who are vulnerable to crashing flaws are Cypress, NXP, Dialog Semiconductors, Texas Instruments, Microchip, and Telink Semiconductor. Those susceptible to deadlocks are Cypress NXP, Texas Instruments, and STMicroelectronics. As for the security bypassing, the only vendor plagued by this is Telink Semiconductor.

This creates a big problem for users of wearables, smart home IoT devices, and even security/surveillance systems. Examples of products that are using the vulnerable SoCs are the Fitbit Inspire range, the Eve Systems, the CubiTag Bluetooth tracker, and the eGee Touch smart lock. Unfortunately, medical products from VivaCheck Laboratories, Medtronic Inc., and others, are also vulnerable. The researchers are demonstrating how they manage to crash a Fitbit Inspire fitness tracker and deadlock a CubiTag in the following video.

So, the question now is, what can the users do to protect themselves from Sweyntooth? Unfortunately, not much other than wait for your product manufacturer to push updates that incorporate the fixing patches that were released by the SoC vendors. Cypress, NXP, Texas Instruments, and Telink, have already released their fixes, but it will take a while to reach the consumers. Even worse, Dialog, Microchip, and STMicroelectronics haven’t released a fixing patch yet. The only way to stay safe for sure is to disable Bluetooth when you’re in places where there are other people in your range.

Update 17/02: The mention of "Syqe Medical Ltd." has been removed from the article as the company has contacted us to inform about an inaccuracy in the researchers' report. While they have secured a license to use BLE technology on their "Inhaler v01" product, the BLE technology has not been enabled. Thus, their products are not vulnerable to SweynTooth attacks.



For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: