arrow
Return

Uncovering Bluetooth vulnerabilities with binary coverage-guided fuzz testing and controller emulation

delete2026-04-25
delete0
PRE
AI
Z
Zhao Min Chen
T
Tien-Chih Lin
G
Guan-Yan Yang
Y
Yu-Sheng Lin
F
Farn Wang
K
Kuo‐Hui Yeh *
DOI:10.1016/j.cose.2026.104929delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
• We present FuBuKi, a binary-rehosting fuzzing framework for binary-only Bluetooth BR/EDR host stacks that uses HCI emulation and does not require physical Bluetooth hardware. • FuBuKi uses a profile-aware proxy to reach high-level application profiles above L2CAP, enabling coverage-guided fuzzing of stateful targets such as SDP, RFCOMM, and AVRCP. • In fair 24-hour evaluations under both post-handshake and pre-handshake settings, FuBuKi achieves higher code coverage than representative state-of-the-art baselines. • The framework’s efficacy is validated by discovering a potential 0-day vulnerability in a commercial automotive firmware and rediscovering a known CVE in Linux BlueZ.
Keywords:
binary fuzzing
Bluetooth BR/EDR
HCI emulation
coverage-guided fuzzing
vulnerability discovery

Journal

C
COMPUTERS & SECURITY
IF:
5.4
Papers:
185
Citations:
0

Organization

N
National Taiwan University
Scholars:
4.7W
Papers: 4.2W
Citations: 3.6W
N
national yang ming chiao tung university
Scholars:
3.1K
Papers: 1.4K
Citations: 0
C
cycraft technology
Scholars:
5
Papers: 3
Citations: 0
researcher View more organizations