BitChat for iOS version 1.15.0 improperly handles unauthenticated MESSAGE packets submitted to its mesh gossip cache. A remote attacker can send a crafted MESSAGE packet that triggers a denial-of-service condition.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a small standalone Python proof-of-concept repository containing a CC0 license, a short README, and the main implementation in poc.py (approximately 17 KB). It is not part of Metasploit, Nuclei, or another exploit framework. The README describes it as a BLE cache-poisoning PoC for Bitchat 1.15.0; its usage examples refer to barghest.py, but the supplied executable is named poc.py. The Python program uses bleak for BLE scanning/GATT interaction and PyNaCl for generated Noise and Ed25519-style signing material. It scans for Bitchat devices advertising the hard-coded service UUID, optionally selects the first discovered target automatically, then connects to a caller-specified BLE address. It constructs attacker-controlled identity TLVs, message/file-transfer protocol frames, signatures, timestamps, recipient fields where applicable, and BLE-sized fragments before writing them to the target characteristic. CLI controls shown in the code include scanning, explicit/automatic target selection, anonymous peer-ID prefixing, message/file/both send modes, local file metadata, BLE write size, fragment delay, attack window, and send interval. The default demonstrative result is a forged Bitchat message reading "Pwned by BARGHEST" and/or an incoming file, with an embedded minimal PNG available as demo content. No internet C2, fixed victim MAC address, IP address, domain contacted by code, persistence mechanism, shell, or command-execution payload is present. The only operationally relevant target identifiers are the BLE GATT service and characteristic UUIDs.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.