USENIX Security2020Top-tier venue
Frankenstein: Advanced Wireless Fuzzing to Exploit New Bluetooth Escalation Targets
Jan Ruge, Jiska Classen, Francesco Gringoli, Matthias Hollick
Abstract
Wireless communication standards and implementations have a troubled history regarding security. Since most implementations and firmwares are closed-source, fuzzing remains one of the main methods to uncover Remote Code Execution (RCE) vulnerabilities in deployed systems. Generic over-the-air fuzzing suffers from several shortcomings, such as constrained speed, limited repeatability, and restricted ability to debug. In this paper, we present Frankenstein, a fuzzing framework based on advanced firmware emulation, which addresses these shortcomings. Frankenstein brings firmware dumps "back to life", and provides fuzzed input to the chip's virtual modem. The speed-up of our new fuzzing method is sufficient to maintain interoperability with the attached operating system, hence triggering realistic full-stack behavior. We demonstrate the potential of Frankenstein by finding three zero-click vulnerabilities in the Broadcom and Cypress Bluetooth stack, which is used in most Apple devices, many Samsung smartphones, the Raspberry Pis, and many others. Given RCE on a Bluetooth chip, attackers may escalate their privileges beyond the chip's boundary. We uncover a Wi-Fi/Bluetooth coexistence issue that crashes multiple operating system kernels and a design flaw in the Bluetooth 5.2 specification that allows link key extraction from the host. Turning off Bluetooth will not fully disable the chip, making it hard to defend against RCE attacks. Moreover, when testing our chip-based vulnerabilities on those devices, we find BlueFrag, a chip-independent Android RCE.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers37
- Nyx-net: network fuzzing with incremental snapshotsSergej Schumilo, Cornelius Aschermann, Andrea Jemmett, Ali Abbasi et al.EuroSys 2022 · 76 citations
- Automatic Firmware Emulation through Invalidity-guided Knowledge InferenceWei Zhou, Le Guan, Peng Liu, Yuqing ZhangUSENIX Security 2021 · 76 citations
- SoK: Prudent Evaluation Practices for FuzzingMoritz Schloegel, Nils Bars, Nico Schiller, Lukas Bernhard et al.S&P 2024 · 69 citations
- Method Confusion Attack on Bluetooth PairingMaximilian von Tschirschnitz, Ludwig Peuckert, Fabian Franzen, Jens GrossklagsS&P 2021 · 42 citations
- LIGHTBLUE: Automatic Profile-Aware Debloating of Bluetooth StacksJianliang Wu, Ruoyu Wu, Daniele Antonioli, Mathias Payer et al.USENIX Security 2021 · 38 citations
Builds on7
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel et al.USENIX Security 2017 · 324 citations
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 187 citations
- Touching the Untouchables: Dynamic Security Analysis of the LTE Control PlaneHongil Kim, Jiho Lee, Eunkyu Lee, Yongdae KimS&P 2019 · 174 citations
- GRIMOIRE: Synthesizing Structure while FuzzingTim Blazytko, Cornelius Aschermann, Moritz Schlögel, Ali Abbasi et al.USENIX Security 2019 · 123 citations
- The KNOB is Broken: Exploiting Low Entropy in the Encryption Key Negotiation Of Bluetooth BR/EDRDaniele Antonioli, Nils Ole Tippenhauer, Kasper Bonne RasmussenUSENIX Security 2019 · 89 citations
Related papers
- BrakTooth: Causing Havoc on Bluetooth Link Manager via Directed FuzzingMatheus E. Garbelini, Vaibhav Bedi, Sudipta Chattopadhyay, Sumei Sun et al.USENIX Security 2022
- BaseBridge: Bridging the Gap Between Over-the-Air and Emulation Testing for Cellular Baseband FirmwareDaniel Klischies, Dyon Goos, David Hirsch, Alyssa Milburn et al.S&P 2025
- BSFuzzer: Context-Aware Semantic Fuzzing for BLE Logic Flaw DetectionTing Yang, Yue Qin, Lan Zhang, Zhiyuan Fu et al.NDSS 2026 · 1 citation
- Bluetooth Low Energy Security Testing with Combinatorial MethodsDominik-Philip Schreiber, Manuel Leithner, Jovan Zivanovic, Dimitris E. SimosUSENIX ATC 2025 · 1 citation
- Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege EscalationJiska Classen, Francesco Gringoli, Michael Hermann, Matthias HollickS&P 2022 · 16 citations
