Bluetooth Stack Gaps in Automotive IVI: Mapping BlueSDK (PerfektBlue) Vulnerabilities to the CIA Triad

Bluetooth is a widely used wireless interface for in-vehicle infotainment (IVI) systems, yet the security posture of the embedded stacks that implement it rarely receives the same scrutiny as the protocol itself. This paper analyzes OpenSynergy's BlueSDK, a closed-source Bluetooth framework deployed across multiple automotive OEMs, using a five-axis qualitative framework covering protocol layer, impact severity, proximity/band context, attack surface breadth, and standards alignment. PerfektBlue — a chain of four CVEs disclosed in 2025 — is used as a case study. PCA Cyber Security demonstrated the complete exploit chain on vulnerable BlueSDK-based IVI platforms and separately confirmed PerfektBlue-related vulnerabilities in BMW vehicles, where an information leak was demonstrated but remote code execution was not completed during that research. The analysis draws exclusively on public advisories, CVE records, and vendor disclosures; no new exploitation work was performed. We find that the disclosed defects are implementation-level flaws rather than demonstrated weaknesses in the Bluetooth specification. At the CIA level, the direct mechanisms do not map uniformly to a single property: most exploit stages are primarily associated with integrity, while CVE-2024-45432 is directly associated with confidentiality because its public description identifies sensitive-information disclosure. At the chain level, successful RCE can affect confidentiality, integrity, and availability. OpenSynergy reported that patches were rolled out in September 2024, while PCA reported that not all affected OEMs had received the patch by June 2025, highlighting the distinction between component-level patch availability and downstream remediation. The paper closes with hardening recommendations and a discussion of residual risk in automotive Bluetooth deployments. Keywords: Bluetooth Security, Automotive IVI, BlueSDK, PerfektBlue, CIA Triad, Vulnerability Management, Automotive Cybersecurity, Supply-Chain Security, Use-After-Free

Authors

Institutions

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-09-28
DOI
https://doi.org/10.5281/zenodo.23003708
Primary Topic
Bluetooth and Wireless Communication Technologies
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
preprint

Bluetooth Stack Gaps in Automotive IVI: Mapping BlueSDK (PerfektBlue) Vulnerabilities to the CIA Triad

Rahim Alizada
Zenodo (CERN European Organization for Nuclear Research)
Bluetooth and Wireless Communication Technologies
preprint

Bluetooth Stack Gaps in Automotive IVI: Mapping BlueSDK (PerfektBlue) Vulnerabilities to the CIA Triad

Rahim Alizada
preprint en

Abstract

Bluetooth is a widely used wireless interface for in-vehicle infotainment (IVI) systems, yet the security posture of the embedded stacks that implement it rarely receives the same scrutiny as the protocol itself. This paper analyzes OpenSynergy's BlueSDK, a closed-source Bluetooth framework deployed across multiple automotive OEMs, using a five-axis qualitative framework covering protocol layer, impact severity, proximity/band context, attack surface breadth, and standards alignment. PerfektBlue — a chain of four CVEs disclosed in 2025 — is used as a case study. PCA Cyber Security demonstrated the complete exploit chain on vulnerable BlueSDK-based IVI platforms and separately confirmed PerfektBlue-related vulnerabilities in BMW vehicles, where an information leak was demonstrated but remote code execution was not completed during that research. The analysis draws exclusively on public advisories, CVE records, and vendor disclosures; no new exploitation work was performed. We find that the disclosed defects are implementation-level flaws rather than demonstrated weaknesses in the Bluetooth specification. At the CIA level, the direct mechanisms do not map uniformly to a single property: most exploit stages are primarily associated with integrity, while CVE-2024-45432 is directly associated with confidentiality because its public description identifies sensitive-information disclosure. At the chain level, successful RCE can affect confidentiality, integrity, and availability. OpenSynergy reported that patches were rolled out in September 2024, while PCA reported that not all affected OEMs had received the patch by June 2025, highlighting the distinction between component-level patch availability and downstream remediation. The paper closes with hardening recommendations and a discussion of residual risk in automotive Bluetooth deployments. Keywords: Bluetooth Security, Automotive IVI, BlueSDK, PerfektBlue, CIA Triad, Vulnerability Management, Automotive Cybersecurity, Supply-Chain Security, Use-After-Free

Zenodo (CERN European Organization for Nuclear Research)
Azerbaijan State Oil and Industry University (AZ)
Bluetooth and Wireless Communication Technologies
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

Bluetooth Stack Gaps in Automotive IVI: Mapping BlueSDK (PerfektBlue) Vulnerabilities to the CIA Triad — Rahim Alizada · Zenodo (CERN European Organization for Nuclear Research) (2026) | TGRS Research Map | TGRS