Armis Labs disclosed BlueBorne, a cluster of Bluetooth implementation vulnerabilities that exposed Android, Windows, Linux, older iOS versions, and some older macOS systems to attack without pairing, user interaction, or even an IP connection. The flaws, reported as eight to nine bugs across affected platforms, included remote code execution, man-in-the-middle, information disclosure, and full device takeover scenarios. Researchers said an infected device could invisibly reach nearby targets over Bluetooth from roughly 32 feet away, potentially intercept data, deliver malware, and spread in a worm-like fashion across phones, PCs, smartwatches, TVs, cars, drones, medical devices, and other IoT systems.
At disclosure, Armis estimated 5.3 billion devices were vulnerable, and US-CERT warned that millions of unpatched systems could be affected. Although patches were issued for some platforms, including Microsoft Windows and newer Android releases, older Android devices, many Linux systems, and unsupported Apple devices remained difficult to secure. A year after the flaws were revealed, Armis said more than two billion devices were still exposed because users had not installed updates or their hardware no longer received vendor support, underscoring the long tail of Bluetooth risk across legacy and embedded systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
About one year after BlueBorne's disclosure, Armis said more than two billion devices remained vulnerable because many users had not installed updates and many older devices no longer received vendor support. The remaining exposed population was said to include large numbers of Linux, Android, Windows, and older iOS devices.
Following disclosure, guidance was issued to apply available vendor patches, update to protected OS versions, and disable or limit Bluetooth where updates were unavailable. Microsoft and supported Android versions had patches available, while US-CERT warned that millions of unpatched phones, computers, wearables, and IoT devices could remain exposed.
Armis publicly disclosed BlueBorne, a set of eight Bluetooth implementation zero-day vulnerabilities affecting Android, Windows, Linux, older iOS versions, and some older macOS versions. The flaws allowed attacks without pairing or user interaction and could enable remote code execution, man-in-the-middle attacks, information disclosure, or full device takeover.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourceweb.archive.org
Open sourceeweek.com
Open sourcetechcrunch.com
Open sourcecsoonline.com
Open sourcezdnet.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.