Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a22ff8cbdebaa68e

Jump to content

// Workers AI · dad joke modeWhat did PerfektBlue say to its friend? "You're dye-namite

From Wikipedia, the free encyclopedia

PerfektBlue is the name given to a chain of four security vulnerabilities in BlueSDK, a Bluetooth protocol stack developed by OpenSynergy and used in automotive in-vehicle infotainment (IVI) systems.[1][2] The vulnerabilities, which have each been assigned a CVE, were discovered and named by researchers at the cybersecurity company PCA Cyber Security (formerly PCAutomotive) and disclosed publicly in July 2025.[3] According to the researchers, the vulnerabilities could be chained into a wireless Bluetooth attack that requires at most one user interaction.[1] At the time of disclosure, vehicles from Mercedes-Benz, Volkswagen, and Škoda were confirmed to have been affected.[1][4][5]

Background

[edit]

BlueSDK is a Bluetooth software development kit and protocol stack that can be integrated into a range of operating systems.[6] It supports both Classic and Low Energy modes, and it implements a large set of Bluetooth profiles.[7] The stack is licensed by the Bluetooth Special Interest Group and is embedded in automotive products.[6] According to OpenSynergy, BlueSDK has shipped in about 350 million cars and is present in more than a billion embedded devices worldwide, including consumer, mobile, industrial, and medical products.[8]

Infotainment vulnerabilities

[edit]

PerfektBlue consists of four vulnerabilities that, if combined, could potentially let an attacker run arbitrary code after establishing a Bluetooth connection.[3]

  • CVE-2024-45434 (Critical Severity): Use-After-Free (a specific kind of memory error) in Audio/Video Remote Control Profile (AVRCP) service.[9][8]
  • CVE-2024-45433 (Medium Severity): Incorrect function termination in Radio Frequency Communication (RFCOMM).[10]
  • CVE-2024-45432 (Medium Severity): Function call with incorrect parameter in RFCOMM.[11]
  • CVE-2024-45431 (Low Severity): Improper validation of a Logical Link Control and Adaptation Protocol (L2CAP) channel's remote Channel Identifier (CID).[12][8]

Exploitation

[edit]

To carry out a PerfektBlue attack, the vulnerabilities are chained together to achieve remote code execution.[3]

An attacker must be within Bluetooth range of the target, with the target accepting pairing.[2] On the devices tested, the vulnerabilities were reachable after pairing, although researchers said that on some implementations, they may be reachable before pairing, depending on the profile security level chosen by the developer or the use of the "Just Works" Secure Simple Pairing mode.[7]

After an attacker compromises the infotainment unit, they could theoretically access the GPS location, the microphone, and stored contact lists.[3] According to researchers, weak network segmentation could theoretically let attackers reach other vehicle systems, though that would hinge on further vulnerabilities and how each vehicle is built.[2]

Researchers demonstrated proof-of-concept exploits on infotainment units from Mercedes (Mercedes-Benz NTG6 head units), Volkswagen (Volkswagen MEB ICAS3 infotainment system used in the ID.4), and Škoda (MIB3 head unit used in the Superb).[2]

Disclosure

[edit]

PCA Cyber Security reported the vulnerabilities to OpenSynergy in May 2024.[1] OpenSynergy confirmed them and started working on patches in mid-July 2024, with the patches released to customers in September 2024.[7] In March 2025, researchers shared the text of the PerfektBlue advisory website with OpenSynergy for review, and by early June, confirmed that the vulnerabilities were affecting several models from a particular carmaker, which they then notified.[7] Researchers notified OpenSynergy that it was going to publish its advisory in early July 2025.[7] By 23 June, one of the affected carmakers said that it had not received the patch, which had been available since September 2024. The advisory was published on 7 July 2025, with the carmaker unnamed.[7]

Responses

[edit]

OpenSynergy said it was helping customers but that due to non-disclosure agreements, it could not share which carmakers and models were affected.[1]

Mercedes-Benz, one of the carmakers affected, said that external security researchers had notified it about the OpenSynergy BlueSDK framework in November 2024 and that it had taken the measures needed to mitigate risk.[1]

Volkswagen, which was also affected, said the issue was limited to infotainment functions. According to the carmaker, an attack would only be successful if the vehicle was in pairing mode, the pairing request was actively approved by the driver, and the attacker was within about 5 to 7 meters. Even where an attack succeeded, Volkswagen said, critical vehicle functions would stay out of the attacker's reach. It also said that it was rolling out updates and advising owners to check pairing codes before accepting them.[3]

Mikhail Evdokimov, a senior security researcher at PCA Cyber Security, disputed some of Volkswagen's conditions, saying that on the Volkswagen ID.4 and Škoda Superb, the infotainment system can be activated without the ignition on, and that pairing can be initiated remotely without the user placing the system in pairing mode. [8]

[edit]

In separate research, the National Cybersecurity Agency of France (ANSSI) analyzed the same OpenSynergy BlueSDK stack and demonstrated a zero-click remote code execution attack on an unnamed premium vehicle's infotainment unit, exploiting a vulnerability similar to the earlier CVE-2018-20378 and bypassing ASLR and DEP mitigations. [13]

References

[edit]
  1. 1 2 3 4 5 6 Toulas, Bill. "PerfektBlue Bluetooth flaws impact Mercedes, Volkswagen, Skoda cars". BleepingComputer. Retrieved 2026-06-04.
  2. 1 2 3 4 Otto, Greg (2025-07-11). "Researchers identify critical vulnerabilities in automotive Bluetooth systems". CyberScoop. Retrieved 2026-06-04.
  3. 1 2 3 4 5 Lakshmanan, Ravie (July 11, 2025). "PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution". The Hacker News. Retrieved 2026-06-04.
  4. Kovacs, Eduard (2025-07-10). "Millions of Cars Exposed to Remote Hacking via PerfektBlue Attack". SecurityWeek. Retrieved 2026-06-04.
  5. published, Sead Fadilpašić (2025-07-11). "Bluetooth security flaws could affect thousands of Mercedes, Volkswagen, Skoda cars - here's what we know". TechRadar. Retrieved 2026-06-04.
  6. 1 2 Evdokimov, Mikhail (2025-07-03). "Critical Vulnerabilities Blue SDK OpenSynergy | PCA Advisory". pcacybersecurity.com. Retrieved 2026-06-04.
  7. 1 2 3 4 5 6 Paganini, Pierluigi (2025-07-10). "PerfektBlue Bluetooth attack allows hacking infotainment systems of Mercedes, Volkswagen, and Skoda". Security Affairs. Retrieved 2026-06-04.
  8. 1 2 3 4 "350M Cars, 1B Devices Exposed to 1-Click Bluetooth RCE". Dark Reading. Retrieved 2026-06-04.
  9. "NVD - CVE-2024-45434". nvd.nist.gov. Retrieved 2026-06-04.
  10. "NVD - CVE-2024-45433". nvd.nist.gov. Retrieved 2026-06-04.
  11. "NVD - CVE-2024-45432". nvd.nist.gov. Retrieved 2026-06-04.
  12. "NVD - CVE-2024-45431". nvd.nist.gov. Retrieved 2026-06-04.
  13. Trébuchet, Philippe; Bouffard, Guillaume (July 2026). "Revisiting Bluetooth Vulnerabilities in Automotive Infotainment Systems: A Remote Code Execution Case Study". Workshop on Automotive Cyber Security. Lisbonne, Portugal.