Source Link Privacy.
Tarlogic Security has detected a backdoor in the ESP32, a microcontroller that enables WiFi and Bluetooth connection and is present in millions of mass-market IoT devices. Exploitation of this backdoor would allow hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls.
Update: The ESP32 “backdoor” that wasn’t.
I wonder which IoT devices are affected, beyond DIY, that people actually use in North America.
I have a cheap wireless hygrometer in the house… I don’t know which chip gives it its capability. I just know ESP32 is the most common one.