This repository contains the implementation of a proof of concept to record and replay audio from a bluetooth device without the legitimate user's awareness.
This proof of concept exploits the failure to comply with the BSAM-PA-05 control within the BSAM methodology. Consequently, the device enables the pairing procedure without requiring user interaction and exposes its functionality to any agent within the signal range. https://github.com/TarlogicSecurity/BlueSpy