Return
Uncovering Bluetooth vulnerabilities with binary coverage-guided fuzz testing and controller emulation
DOI:10.1016/j.cose.2026.104929.png)
Abstract
En 中文
• We present FuBuKi, a binary-rehosting fuzzing framework for binary-only Bluetooth BR/EDR host stacks that uses HCI emulation and does not require physical Bluetooth hardware. • FuBuKi uses a profile-aware proxy to reach high-level application profiles above L2CAP, enabling coverage-guided fuzzing of stateful targets such as SDP, RFCOMM, and AVRCP. • In fair 24-hour evaluations under both post-handshake and pre-handshake settings, FuBuKi achieves higher code coverage than representative state-of-the-art baselines. • The framework’s efficacy is validated by discovering a potential 0-day vulnerability in a commercial automotive firmware and rediscovering a known CVE in Linux BlueZ.
Keywords:
binary fuzzing
Bluetooth BR/EDR
HCI emulation
coverage-guided fuzzing
vulnerability discovery
Journal
C
IF:
5.4
Papers:
185
Citations:
0

