1028
Undocumented Commands Found In Bluetooth Chip Manufactured in China Used By a Billion Devices.
(www.tarlogic.com)
This is a most excellent place for technology news and articles.
Well... Shit.
There are so, so, so, many ESP32's in not just my house, but practically everyone I know.
There outta be fines for this BS.
You're fine. This isn't something that can be exploited over wifi. You literally need physical access to the device to exploit it as it's commands over USB that allow flashing the chip.
This is a security firm making everything sound scary because they want you to buy their testing device.
You don't need physical access. Read the article. The researcher used physical USB to discover that the Bluetooth firmware has backdoors. It doesn't require physical access to exploit.
It's Bluetooth that's vulnerable.
https://www.bleepingcomputer.com/news/security/undocumented-backdoor-found-in-bluetooth-chip-used-by-a-billion-devices/
This is about silicon. Undocumented instructions have just been found in it but they are not executable unless the ESP32's firmware uses them. Firmware cannot be edited to use them unless you have an existing vulnerability such as physical access or insecure OTA in existing firmware (as far as researchers know).