BLEWhisperer: Exploiting BLE Advertisements for Data Exfiltration
Ankit Gangwal, Shubham Singh, Riccardo Spolaor, Abhijeet Srivastava

TL;DR
This paper demonstrates how BLE advertisements can be exploited by attackers to exfiltrate data from devices without authentication, highlighting a new security vulnerability in BLE technology.
Contribution
The paper introduces a novel attack framework exploiting BLE advertisements for covert data exfiltration without prior pairing or authentication.
Findings
Exfiltration is feasible with limited data rate
Attack works on Android devices
Potential for more severe attack enhancements
Abstract
Bluetooth technology has enabled short-range wireless communication for billions of devices. Bluetooth Low-Energy (BLE) variant aims at improving power consumption on battery-constrained devices. BLE-enabled devices broadcast information (e.g., as beacons) to nearby devices via advertisements. Unfortunately, such functionality can become a double-edged sword at the hands of attackers. In this paper, we primarily show how an attacker can exploit BLE advertisements to exfiltrate information from BLE-enable devices. In particular, our attack establishes a communication medium between two devices without requiring any prior authentication or pairing. We develop a proof-of-concept attack framework on the Android ecosystem and assess its performance via a thorough set of experiments. Our results indicate that such an exfiltration attack is indeed possible though with a limited data rate.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsBluetooth and Wireless Communication Technologies · Opportunistic and Delay-Tolerant Networks · Privacy, Security, and Data Protection
