On Fri, 2018-07-20 at 13:23 +0200, Bastien Nocera wrote: > <snip> > This means that a combination of a hard-to-use API for > Discoverable[3], > and the kernel's default policy, will allow devices such as iPhones > to > pair without any interaction on the computer/BlueZ side. This particular problem has been assigned a CVE: CVE-2018-10910 Would be great if I could have some feedback on this. -- To unsubscribe from this list: send the line "unsubscribe linux-bluetooth" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html