CVE-2023-45866 is an improper-authentication vulnerability in Bluetooth HID host implementations, including BlueZ. A device acting as a Bluetooth Peripheral-role HID keyboard can initiate and establish an encrypted connection and submit HID keyboard reports without prior user authorization on the Central-role host. The authentication bypass permits spoofed keyboard input to be accepted despite the absence of an approved pairing or connection interaction. The issue affected Bluetooth implementations in Linux/BlueZ and was also addressed in Android, iOS, iPadOS, and macOS.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a real exploit toolkit for CVE-2023-45866, packaged as an operator-friendly Bluetooth HID impersonation attack chain against vulnerable Android devices. It is not just a detector or documentation set: it contains an interactive Python wizard, a HID report generator, a C-based Bluetooth L2CAP injector, YAML attack profiles, and a Bash driver that orchestrates Bluetooth setup and Metasploit handler startup. Repository structure and purpose: - poc/bt-hid-wizard.py: main entry point. Interactive wizard that collects target MAC/profile choices, performs pre-flight checks, writes build/current-target.env, and launches the attack workflow. - poc/hid_attack.py: converts YAML keystroke profiles into raw 10-byte HID keyboard report frames. It also contains Bluetooth/HID emulation logic and references targeted/opportunistic modes, though in this repo it is mainly used to generate report bytes. - poc/hid_inject.c: core exploit delivery component. Opens raw Bluetooth L2CAP connections to the target’s HID Control and HID Interrupt channels (PSM 0x0011 and 0x0013) and transmits the generated HID frames with timing delays to simulate keyboard input. - poc/troubleshoot.py: helper module for diagnosing environment/setup failures and attempting fixes. - profiles/*.yaml: scripted post-exploitation/abuse sequences. These include install-apk, exfil-sms, exfil-screenshots, and enable-dev-options. - run_attack.sh: orchestration script that enables the local Bluetooth adapter, registers SDP HID services, generates HID reports, optionally starts msfconsole using a Metasploit resource file, compiles/runs the injector, and tails logs. - payloads/README.md: documents a bundled Android Meterpreter reverse HTTPS APK named invoices.apk and its callback configuration. Main exploit capabilities: 1. Bluetooth HID impersonation against vulnerable Android devices without normal pairing validation. 2. Automated keystroke injection over Bluetooth to drive the target UI. 3. Installation of a malicious Android APK from /sdcard/Download/invoices.apk. 4. Launch of a Meterpreter reverse HTTPS payload that calls back to 0xbadactor.duckdns.org:443. 5. Non-payload actions such as opening Messages and scrolling SMS, taking screenshots of sensitive apps/data, and enabling Developer Options plus USB debugging. Although the repository includes custom code, it clearly integrates with Metasploit for payload generation/handling, so the overall maturity is weaponized rather than a simple PoC. The exploit is intended for nearby wireless attack scenarios and requires the victim device to be vulnerable, unlocked, and within Bluetooth range.
Repository implements a Bluetooth HID injection tool branded “BlueDucky” targeting CVE-2023-45866 (unauthenticated pairing/peering leading to keystroke injection). The main entry point is BlueDucky.py, which orchestrates: (1) target selection (manual MAC or scan/known_devices.txt), (2) BlueZ adapter setup via hciconfig and DBus, (3) running a “NoInputNoOutput” pairing agent, (4) registering a HID keyboard profile with BlueZ (HID UUID 00001124… and an embedded SDP XML record), and (5) establishing HID/L2CAP connections to send keyboard reports. Core structure: - BlueDucky.py: main controller; sets up logging, Bluetooth adapter, pairing agent, connection management, and processes DuckyScript payloads. Includes reconnection logic to resume from a specific script line/position after disconnects. - utils/menu_functions.py: UI/menus, Bluetooth discovery, MAC validation, persistence of discovered devices to known_devices.txt, and DuckyScript file loading. - utils/register_device.py: DBus/BlueZ Agent1 and Profile1 registration; registers HID profile using a hardcoded SDP XML ServiceRecord. - utils/magic_keyboard_hid.py: HID keycode enum mapping used to translate DuckyScript tokens into HID reports. - payloads/: multiple ready-to-run DuckyScript payloads for Windows/Linux/macOS, including defense tampering (disable UAC/Defender), bind/reverse shells (netcat, /dev/tcp), persistence via cron, HTTP file exposure via python http.server, credential/WiFi dumping, and demo/annoyance scripts (rickroll, forkbomb). Some payloads contain placeholders (e.g., [IP], [WEBHOOK URL]) and at least one Windows “dumpcreds” script appears incomplete. Overall purpose: provide an operator-friendly Bluetooth offensive tool to impersonate a keyboard over Bluetooth and inject keystrokes into vulnerable devices, enabling post-exploitation actions entirely through HID input without prior authentication.
This repository implements an exploit for CVE-2023-45866, targeting Bluetooth devices vulnerable to unauthenticated HID pairing. The main script, BlueDucky.py, is a Python tool that allows an attacker to scan for, pair with, and send keystroke payloads (in DuckyScript format) to Bluetooth devices, effectively impersonating a keyboard. The tool is designed to run on Linux systems (notably Raspberry Pi) and leverages the BlueZ stack and related Python libraries for Bluetooth communication. The payloads directory contains example DuckyScript files that automate actions such as opening browsers or launching applications on the target device. The exploit's main capability is remote code execution via keystroke injection over Bluetooth, without user interaction on the target. The repository is well-structured, with clear installation and usage instructions, and is operational with customizable payloads. No hardcoded network endpoints or IP addresses are present; the main fingerprintable elements are the payload files and the use of a local known_devices.txt file for device management.
This repository, 'rusty_injector', is a Rust-based proof-of-concept exploit for CVE-2023-45866, targeting the BlueZ Bluetooth stack on Linux. The exploit leverages a vulnerability in the handling of Bluetooth HID (Human Interface Device) profiles, allowing an attacker to impersonate a keyboard and inject arbitrary keystrokes into a target system over Bluetooth BR/EDR. The code is structured as a Rust project with a main entry point in 'src/main.rs', which handles Bluetooth adapter configuration, profile registration, and the keystroke injection logic. Supporting modules in 'src/utils/' provide helper functions for Bluetooth address validation, HID report construction, and adapter manipulation. The exploit requires the attacker to configure their Bluetooth adapter to appear as a keyboard, register a custom HID profile (using 'keyboard.xml'), and connect to the target's Bluetooth address on specific L2CAP channels (ports 17 and 19). The README provides detailed setup instructions, including necessary changes to the BlueZ service configuration. The exploit is operational as a PoC, demonstrating the ability to inject keystrokes (such as 'Hello' and Tab) into the target system for a set duration. No detection or post-exploitation features are present; the focus is on demonstrating the keystroke injection vector. The repository is not part of a larger framework and is self-contained.
This repository, 'blueXploit', is an operational exploit toolkit targeting critical Bluetooth vulnerabilities (notably CVE-2023-45866 and CVE-2024-21306) affecting Android, Linux, macOS, iOS, and Windows. The main exploit (blueXploit.py) leverages flaws in the Bluetooth HID and L2CAP protocols to inject keystrokes into target devices without user interaction or pairing, enabling remote command execution. The toolkit also includes an APK payload injector (injector/apkpwn_injector.py) that automates the creation and injection of Android Meterpreter reverse TCP payloads into APKs, serving them via a local HTTP server for social engineering attacks. Payloads are defined in DuckyScript-like text files and can be customized for specific attack scenarios. The codebase is primarily Python, with supporting Bash scripts for banners. The exploit requires a Linux system with a compatible Bluetooth adapter and several dependencies. The repository is well-documented, with a detailed README explaining the vulnerabilities, affected systems, and attack methodology. The exploit is operational and can be used for real-world attacks in penetration testing or red team scenarios.
This repository contains a collection of keystroke injection payloads written in Ducky Script, intended for use with devices like the USB Rubber Ducky. The payloads automate a variety of malicious actions on a victim's Windows or Android device, including brute-forcing lock screen passwords (bruteforce.txt), opening phishing URLs to access the victim's camera (camphish1.txt), downloading malicious files (downloads.txt), installing APKs (maliciousapk.txt), uploading files (payload_example_1.txt), and sending WhatsApp messages (whatsapp.txt). The scripts rely on the attacker's ability to physically connect a keystroke injection device to the target system, making the attack vector local. Several fingerprintable endpoints are hardcoded in the payloads, including URLs for phishing, file download/upload, and messaging. The repository is structured as a set of standalone payload scripts, each targeting a specific malicious action, and is suitable for penetration testing or red teaming scenarios where physical access to the target is possible.
The BlueDucky repository is an operational exploit tool targeting CVE-2023-45866, a vulnerability in Bluetooth HID pairing that allows unauthenticated devices to connect as keyboards and inject keystrokes. The main script, BlueDucky.py, orchestrates the attack by scanning for Bluetooth devices, managing known devices, and establishing a malicious HID connection to the target. Payloads are written in DuckyScript, a simple scripting language for keyboard automation, and are stored in the 'payloads/' directory. The tool is designed for use on Linux systems (tested on Raspberry Pi) and leverages the BlueZ stack and Python libraries for Bluetooth communication. The exploit enables an attacker to execute arbitrary keystrokes on a vulnerable target, potentially leading to code execution or other malicious actions. The repository includes utility modules for device registration and menu functions, and stores discovered device information in 'known_devices.txt'.
This repository implements a practical exploit for CVE-2023-45866, a vulnerability allowing unauthenticated Bluetooth remote code execution by emulating a Bluetooth keyboard and injecting keystrokes into a target device without pairing. The main entry point is BluetoothDucky.py, which orchestrates the attack by initializing the Bluetooth adapter, registering a HID profile (using keyboard.xml), and connecting to the target device's Bluetooth address. The exploit reads DuckyScript commands from payload.txt and translates them into HID keyboard reports, which are sent over Bluetooth L2CAP channels to the target. The code is modular, with the 'injector' directory containing helper modules for Bluetooth communication, HID report generation, DuckyScript parsing, and device pairing. The README provides setup instructions and usage examples. The exploit is operational and has been tested on various phones, requiring only the target's Bluetooth MAC address and proximity. No network endpoints or IP addresses are hardcoded; the primary fingerprintable elements are the Bluetooth MAC address of the target and the use of the HID profile as defined in keyboard.xml.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bluetooth-related issue where a privileged network attacker could inject keystrokes by spoofing a keyboard; fixed with improved checks.
Unknown
Critical Bluetooth protocol implementation flaw enabling unauthenticated keystroke injection via an authentication/confirmation bypass, potentially allowing arbitrary command execution or malicious app installation.
A Bluetooth HID (Human Interface Device) host issue in BlueZ that can allow an unauthenticated peripheral (e.g., a rogue keyboard) to establish an encrypted connection and inject HID keyboard reports without user authorization/interaction, enabling keystroke injection.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.