Hallo zusammen,
sofern nicht selber schon gesehen/-lesen hier [0] FYI
"Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing"
--> critical vulnerabilities (CVE-2023-45866, CVE-2024-21306) in Bluetooth
--> can be exploited to inject keystrokes without user confirmation – by accepting any Bluetooth pairing request
--> affect Android, Linux, macOS, iOS, and Windows operating systems
ein PoC findet sich auf [1]
VG
Bernd
[0] https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetoot...
[1] https://github.com/marcnewlin/hi_my_name_is_keyboard
rwth-security@lists.rwth-aachen.de