Back to search
CVE-2020-6616
Published: May 8, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (PRNG) is used in situations where a Hardware Random Number Generator (HRNG) should have been used to prevent spoofing. This affects, for example, Samsung Galaxy S8, S8+, and Note8 devices with the BCM4361 chipset. The Samsung ID is SVE-2020-16882 (May 2020).
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://security.samsungmobile.com/securityUpdate.smsb
x_refsource_CONFIRM
https://support.apple.com/kb/HT211100
x_refsource_CONFIRM
http://bluetooth.lol
x_refsource_MISC
https://twitter.com/naehrdine/status/1255981245147877377
x_refsource_MISC
https://twitter.com/naehrdine/status/1255980443368919045
x_refsource_MISC
https://support.apple.com/kb/HT211168
x_refsource_CONFIRM
20200529 APPLE-SA-2020-05-26-1 iOS 13.5 and iPadOS 13.5
mailing-list
x_refsource_FULLDISC
https://support.apple.com/HT211168
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now