Secret commands found in Bluetooth chip used in a billion devices

Researchers discovered what they're describing as a potential security issue that could affect a billion devices.
By  on 
Bluetooth logo
Security researchers have discovered dozens of undocumented commands hidden in a Bluetooth chip found in billions of devices. Credit: Silas Stein/picture alliance via Getty Images

A potential security issue has been discovered by cybersecurity researchers that has the capability to affect more than one billion devices.

According to researchers at the cybersecurity firm Tarlogic, a hidden command has been found coded into a bluetooth chip installed in devices around the world. This secret functionality can be weaponized by bad actors and, according to the researchers, used as an exploit into these devices.

Using these commands, hackers could impersonate a trusted device and then connect to smartphones, computers, and other devices in order to access information stored on them. Bad actors can continue to utilize their connection to the device to essentially spy on users.

The bluetooth chip is called ESP32 and is manufactured by the China-based company Espressif. According to researchers, the ESP32  is "a microcontroller that enables WiFi and Bluetooth connection." In 2023, Espressif reported that one billion units of its ESP32 chip had been sold globally. Millions of IoT devices like smart appliances utilize this particular ESP32 chip.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

Tarlogic researchers say that this hidden command could be exploited, which would allow  "hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls." Tarlogic says that these commands are not publicly documented by Espressif.

Researchers with Tarlogic developed a new Bluetooth driver tool in order to aid in Bluetooth-related security research, which enabled the security firm to discover a total of 29 hidden functionalities that could be exploited to impersonate known devices and access confidential information stored on a device. 

According to Tarlogic, Espressif sells these bluetooth chips for roughly $2, which explains why so many devices utilize the component over higher costing options.

As BleepingComputer reports, the issue is being tracked as CVE-2025-27840.


Recommended For You
Figure’s humanoid robot will do your chores with voice commands
Figure's humanoid robots working together to put away groceries

The 10 best Amazon Echo devices for a smarter home
amazon echo show 10 on kitchen counter with plate of toast in foreground


Keep track of what matters: The Tile Bluetooth tracker is 28% off at Amazon
A square black Tile by Life360 Mate tracker with a small hole in the corner, resting on a gradient teal and light green background. The word "tile" is visible in small letters in the lower right corner.


Trending on Mashable
NYT Connections hints today: Clues, answers for March 13, 2025
A close-up of an NYT Connections game on a smartphone.

NYT Connections hints today: Clues, answers for March 12, 2025
A close-up of an NYT Connections game on a smartphone.

Wordle today: Answer, hints for March 13, 2025
A close-up of a Wordle game open on a smartphone.

NYT Strands hints, answers for March 13
A game being played on a smartphone.

Wordle today: Answer, hints for March 12, 2025
A close-up of a Wordle game open on a smartphone.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!