Bluetooth Security Vulnerability Discovered, but Apple's Fix is Already in Place - MacRumors
Skip to Content

Bluetooth Security Vulnerability Discovered, but Apple's Fix is Already in Place

by

BluetoothIconXA newly discovered Bluetooth vulnerability that was published this week by Intel has the potential to allow a nearby hacker to gain unauthorized access to a device, intercepting traffic and sending forged pairing messages between two vulnerable Bluetooth devices.

The vulnerability affects Bluetooth implementations and operating system drivers of Apple, Broadcom, Intel, and Qualcomm.

From Intel's explanation:

A vulnerability in Bluetooth(R) pairing potentially allows an attacker with physical proximity (within 30 meters) to gain unauthorized access via an adjacent network, intercept traffic and send forged pairing messages between two vulnerable Bluetooth(R) devices. This may result in information disclosure, elevation of privilege and/or denial of service.

As BleepingComputer explains, Bluetooth-capable devices are not sufficiently validating encryption parameters in "secure" Bluetooth connections, leading to a weak pairing that can be exploited by an attacker to obtain data sent between two devices.

According to the Bluetooth Special Interest Group (SIG) it's not likely many users were impacted by the vulnerability.

For an attack to be successful, an attacking device would need to be within wireless range of two vulnerable Bluetooth devices that were going through a pairing procedure. The attacking device would need to intercept the public key exchange by blocking each transmission, sending an acknowledgment to the sending device, and then injecting the malicious packet to the receiving device within a narrow time window. If only one device had the vulnerability, the attack would not be successful.

Both Bluetooth and Bluetooth LE are affected. Apple has already introduced a fix for the bug on its devices (in macOS High Sierra 10.13.5/10.13.6, iOS 11.4, tvOS 11.4, and watchOS 4.3.1), so iOS and Mac users do not need to worry. Intel, Broadcom, and Qualcomm have also introduced fixes, while Microsoft says its devices are not affected.

Top Rated Comments

Fall Under Cerulean Kites Avatar
103 months ago
This may result in information disclosure, elevation of privilege and/or denial of service.
Bluetooth pairing is so poor as it is, how would one even recognize they were being DoS’d?
Score: 10 Votes (Like | Disagree)
macduke Avatar
103 months ago
Why are Microsoft devices not affected? :oops:
Security through obscurity.
Score: 4 Votes (Like | Disagree)
macintoshmac Avatar
103 months ago
Why are Microsoft devices not affected? :oops:
Score: 4 Votes (Like | Disagree)
m0sher Avatar
103 months ago
I’m just impressed by the time we hear the news, it’s already been fixed. Good job. :)
Score: 3 Votes (Like | Disagree)
103 months ago
Only High Sierra? Did the Sierra security update fix this?
Score: 3 Votes (Like | Disagree)
103 months ago
Why are Microsoft devices not affected? :oops:
Where are you reading that Microsoft products aren't affected? If you click on the first link in the article, it takes you to Intel's research notes on the vulnerability - Windows is listed as the first OS on how to fix the issue.

The vulnerability isn't in the OS, it's in the driver's. Apple produces their own drivers (for the most part), whereas Microsoft/Windows relies on 3rd party drivers from the device manufacturer Thus you wouldn't say Windows is vulnerable, but various Bluetooth devices and drivers are vulnerable on Windows.
Score: 2 Votes (Like | Disagree)

Popular Stories

Chase Sapphire Reserve Apple Perk Feature

Chase Sapphire Preferred Card Introduces New Perk for Apple Customers

Monday June 15, 2026 12:07 pm PDT by
Chase this week announced new perks for its Sapphire Preferred credit card, and one of them is a complimentary one-year Apple TV streaming subscription. To get the free year of Apple TV, which typically costs $12.99 per month in the U.S., you must activate the card by December 31, 2026. If you are already subscribed to Apple TV directly through Apple, the complimentary subscription from...
Chase Sapphire Reserve Apple Perk Feature

New 'Apple One' Perk Extends to Chase's Sapphire Reserve Credit Card

Tuesday June 16, 2026 6:26 am PDT by
Yesterday, we reported that Chase's Sapphire Preferred credit card ($95 annual fee) now offers a complimentary one-year Apple TV streaming subscription, or a $7.50/month discount on an active Apple One subscription instead. It turns out that the Apple One discount now extends to Chase's premium Sapphire Reserve credit card too ($795 annual fee). The Sapphire Reserve has offered free...
Apple Logo Cash Feature Blue

Tim Cook Says Apple Price Increases Are 'Unavoidable' Due to Memory Costs

Wednesday June 17, 2026 2:08 pm PDT by
Apple is raising its prices to offset the high cost of memory and storage, CEO Tim Cook told The Wall Street Journal. Apple is no longer able to absorb the increased prices and will need to pass some of the cost on to consumers. "Unfortunately, price increases are unavoidable," said Cook. "We're doing our best to mitigate the huge increases that are being passed to us, and we've been trying...