USENIX Security2025Top-tier venue
A Thorough Security Analysis of BLE Proximity Tracking Protocols
Xiaofeng Liu, Chaoshun Zuo, Qinsheng Hou, Pengcheng Ren, Jianliang Wu, Qingchuan Zhao, Shanqing Guo
Abstract
Recent advances in Bluetooth Low Energy (BLE) and the ubiquity of mobile infrastructures promote the prevalence of BLE proximity tracking services (e.g., Apple Find My and Samsung Find My Mobile) that use the proximity measured from other surrounding mobile devices (e.g., smartphones). Accordingly, it raises severe security and privacy concerns that are inherent to the basis of the technique (i.e., BLE) and the design of the proximity tracking protocol on top of it. Unfortunately, a systematic and comprehensive analysis of these protocols is still missing since the analysis of these protocols in existing research either focuses on a single participant in the service or lacks formal guarantees. As such, in this paper, we aim to fill in the missing piece by (1) recovering the closed-source protocol via reverse engineering; (2) building formal models based on reverse engineering; (3) extracting and formalizing the designed security goals of these protocols, and (4) formally verifying whether these security goals can be guaranteed. We reverse-engineered and verified two of the most popular real-world proximity tracking services, i.e., Apple Find My and Samsung Find My Mobile. In total, our analysis reveals seven new vulnerabilities confirmed by related vendors, out of which, four CVE/SVE numbers are assigned, including three high-severity vulnerabilities. We also propose mitigations to the discovered vulnerabilities and formally confirm that all security goals can be achieved with our mitigations. At the time of paper writing, Samsung has fixed five vulnerabilities with our assistance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7d99ad8a-79fe-4dc6-8eb7-380e0b3493ffCited by top-tier papers2
- Security and Privacy Analysis of Tile's Location Tracking ProtocolAkshaya Kumar, Anna Raymaker, Michael A. SpecterUSENIX Security 2026 · 1 citation
- Snatcher: Apple Find My Network Exposes Your Lost Devices To StrangersZhenyu Ren, Yanbo Zhang, Boya Liu, Mo LiCCS 2026
Builds on6
- Verified Models and Reference Implementations for the TLS 1.3 Standard CandidateKarthikeyan Bhargavan, Bruno Blanchet, Nadim KobeissiS&P 2017 · 233 citations
- SoK: Computer-Aided CryptographyManuel Barbosa, Gilles Barthe, Karthik Bhargavan, Bruno Blanchet et al.S&P 2021 · 169 citations
- Formal Model-Driven Discovery of Bluetooth Protocol Design VulnerabilitiesJianliang Wu, Ruoyu Wu, Dongyan Xu, Dave Jing Tian et al.S&P 2022 · 36 citations
- Security and Privacy Analysis of Samsung's Crowd-Sourced Bluetooth Location Tracking SystemTingfeng Yu, James Henderson, Alwen Tiu, Thomas HainesUSENIX Security 2024 · 20 citations
- SAPIC+: protocol verifiers of the world, unite!Vincent Cheval, Charlie Jacomme, Steve Kremer, Robert KünnemannUSENIX Security 2022
Related papers
- BLERP: BLE Re-Pairing Attacks and DefensesTommaso Sacchetti, Daniele AntonioliNDSS 2026 · 2 citations
- PrivacyShield: Relaying BLE Beacons to Counter Unsolicited TrackingFlorian Hofhammer, Daniele Antonioli, Mathias PayerUSENIX Security 2026
- Finding Traceability Attacks in the Bluetooth Low Energy Specification and Its ImplementationsJianliang Wu, Patrick Traynor, Dongyan Xu, Dave (Jing) Tian et al.USENIX Security 2024 · 6 citations
- Provable Security Analyses of Google's and Apple's Bluetooth Fast Pair ProtocolsAlexandra Boldyreva, Olga Sanina, Roy StracovskyCRYPTO 2026
- Evaluating Physical-Layer BLE Location Tracking Attacks on Mobile DevicesHadi Givehchian, Nishant Bhaskar, Eliana Rodriguez Herrera, Héctor Rodrigo López Soto et al.S&P 2022 · 55 citations
