Windows and ChromeOS have proper validation of the Simple Secure Pairing (SSP) protocol. As a result, these two OSs remain unaffected by CVE-2023-45866. However, even though it is true that Bluetooth version 4.2 or later was thought to be safe because they added LE Secure Connections (LESC), these features are not necessarily enabled by default. Oftentimes, SDK examples use Legacy pairing to make things easier, and no one makes sure LESC is actually used or working. Many of the attacks on Bluetooth Low Energy (BLE) assume that LESC is being used, because otherwise the security of the device is already compromised. Several vulnerabilities were discovered not so very long ago that clearly demonstrate these risks: CERT/CC Vulnerability Note VU#799380But I currently don't know of any way where modern bluetooth can be connected to a device without the pairing process being in effect.
So, just because these vulnerabilities can be patched, does not necessarily also mean that they have already been patched. Most Windows 10/11 users don't know how to make sure that the internal Bluetooth capability of their laptop has the latest firmware in it. They rarely even understand the importance of keeping drivers always up-to-date, anyway in the first place, so... the "modern" in "modern laptops" is still going to be heavily overrated, especially when you consider the fact that a lot of these people believe that even a 5 year-old laptop is still modern as modern can be.
My Computers
System One System Two
-
- OS
- 11 Home
- Computer type
- Laptop
- Manufacturer/Model
- Asus TUF Gaming F16 (2024)
- CPU
- i7 13650HX
- Memory
- 16GB DDR5
- Graphics Card(s)
- GeForce RTX 4060 Mobile
- Sound Card
- Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
- Monitor(s) Displays
- Sony Bravia XR-55X90J
- Screen Resolution
- 3840×2160
- Hard Drives
- 512GB SSD internal
37TB external
- PSU
- Li-ion
- Cooling
- 2× Arc Flow Fans, 4× exhaust vents, 5× heatpipes
- Keyboard
- Logitech K800
- Mouse
- Logitech G402
- Internet Speed
- 20Mbit/s up, 250Mbit/s down
- Browser
- FF
-
- Operating System
- 11 Home
- Computer type
- Laptop
- Manufacturer/Model
- Medion S15450
- CPU
- i5 1135G7
- Memory
- 16GB DDR4
- Graphics card(s)
- Intel Iris Xe
- Sound Card
- Eastern Electric MiniMax DAC Supreme; Emotiva UMC-200; Astell & Kern AK240
- Monitor(s) Displays
- Sony Bravia XR-55X90J
- Screen Resolution
- 3840×2160
- Hard Drives
- 2TB SSD internal
37TB external
- PSU
- Li-ion
- Mouse
- Logitech G402
- Keyboard
- Logitech K800
- Internet Speed
- 20Mbit/s up, 250Mbit/s down
- Browser
- FF