Bluetooth Stack Gaps in Automotive IVI: Mapping BlueSDK (PerfektBlue) Vulnerabilities to the CIA Triad
Bluetooth is a widely used wireless interface for in-vehicle infotainment (IVI) systems, yet the security posture of the embedded stacks that implement it rarely receives the same scrutiny as the protocol itself. This paper analyzes OpenSynergy's BlueSDK, a closed-source Bluetooth framework deployed across multiple automotive OEMs, using a five-axis qualitative framework covering protocol layer, impact severity, proximity/band context, attack surface breadth, and standards alignment. PerfektBlue — a chain of four CVEs disclosed in 2025 — is used as a case study. PCA Cyber Security demonstrated the complete exploit chain on vulnerable BlueSDK-based IVI platforms and separately confirmed PerfektBlue-related vulnerabilities in BMW vehicles, where an information leak was demonstrated but remote code execution was not completed during that research. The analysis draws exclusively on public advisories, CVE records, and vendor disclosures; no new exploitation work was performed. We find that the disclosed defects are implementation-level flaws rather than demonstrated weaknesses in the Bluetooth specification. At the CIA level, the direct mechanisms do not map uniformly to a single property: most exploit stages are primarily associated with integrity, while CVE-2024-45432 is directly associated with confidentiality because its public description identifies sensitive-information disclosure. At the chain level, successful RCE can affect confidentiality, integrity, and availability. OpenSynergy reported that patches were rolled out in September 2024, while PCA reported that not all affected OEMs had received the patch by June 2025, highlighting the distinction between component-level patch availability and downstream remediation. The paper closes with hardening recommendations and a discussion of residual risk in automotive Bluetooth deployments. Keywords: Bluetooth Security, Automotive IVI, BlueSDK, PerfektBlue, CIA Triad, Vulnerability Management, Automotive Cybersecurity, Supply-Chain Security, Use-After-Free
Authors
- Rahim Alizada
Institutions
- Azerbaijan State Oil and Industry University (AZ)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-28
- DOI
- https://doi.org/10.5281/zenodo.23003708
- Primary Topic
- Bluetooth and Wireless Communication Technologies
- Type
- preprint