PT-2023-1008 · Apple+10 · Ios+11

Marc Newlin

·

Published

2023-08-01

·

Updated

2026-01-08

·

CVE-2023-45866

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BlueZ versions prior to the fixed version Android versions prior to 11 Linux versions with vulnerable Bluetooth stacks macOS versions with vulnerable Bluetooth stacks iOS versions with vulnerable Bluetooth stacks
Description A critical Bluetooth security flaw could be exploited by threat actors to take control of Android, Linux, macOS, and iOS devices. The issue relates to a case of authentication bypass that enables attackers to connect to susceptible devices and inject keystrokes to achieve code execution as the victim. This could lead to remote escalation of privilege with no additional execution privileges needed, and user interaction is not required for exploitation. The estimated number of potentially affected devices worldwide is not specified, but the flaw affects multiple operating systems, including Android, Linux, macOS, and iOS.
Recommendations For BlueZ: Update to a version that includes the fix for the authentication bypass vulnerability. For Android versions prior to 11: No solution is available yet, consider disabling Bluetooth when not in use as a temporary workaround. For Linux versions with vulnerable Bluetooth stacks: Update to a version that includes the fix for the authentication bypass vulnerability. For macOS versions with vulnerable Bluetooth stacks: Update to a version that includes the fix for the authentication bypass vulnerability. For iOS versions with vulnerable Bluetooth stacks: Update to a version that includes the fix for the authentication bypass vulnerability, such as iOS and iPadOS 17.2.

Exploit

Fix

RCE

Improper Authorization

Improper Authentication

Weakness Enumeration

Related Identifiers

ALSA-2024:11154
ALSA-2024:9413
ALSA-2024_11154
ALSA-2024_9413
ASB-A-294854926
AZL-32161
AZL-34571
BDU:2023-08562
CESA-2024_11154
CVE-2023-45866
DLA-3689-1
DSA-5584-1
INFSA-2024_11154
INFSA-2024_9413
MGASA-2023-0353
OESA-2023-1948
OPENSUSE-SU-2024:13507-1
RHSA-2024:11154
RHSA-2024:9413
RHSA-2024_11154
RHSA-2024_9413
RLSA-2024:9413
SUSE-SU-2025:03269-1
SUSE-SU-2025:03277-1
SUSE-SU-2025:03590-1
SUSE-SU-2025:20804-1
SUSE-SU-2025_03590-1
SUSE-SU-2026:20041-1
USN-6540-1

Affected Products

Almalinux
Android
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Ios