{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,2]],"date-time":"2026-01-02T07:36:05Z","timestamp":1767339365490,"version":"3.37.3"},"reference-count":63,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,5,1]],"date-time":"2022-05-01T00:00:00Z","timestamp":1651363200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2022,5,1]],"date-time":"2022-05-01T00:00:00Z","timestamp":1651363200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/501100003090","name":"EWE","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003090","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,5]]},"DOI":"10.1109\/sp46214.2022.9833639","type":"proceedings-article","created":{"date-parts":[[2022,7,27]],"date-time":"2022-07-27T19:28:05Z","timestamp":1658950085000},"page":"1229-1245","source":"Crossref","is-referenced-by-count":12,"title":["Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege Escalation"],"prefix":"10.1109","author":[{"given":"Jiska","family":"Classen","sequence":"first","affiliation":[{"name":"Technical University of Darmstadt, Secure Mobile Networking Lab"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francesco","family":"Gringoli","sequence":"additional","affiliation":[{"name":"University of Brescia, CNIT"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Hermann","sequence":"additional","affiliation":[{"name":"Technical University of Darmstadt, Secure Mobile Networking Lab"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthias","family":"Hollick","sequence":"additional","affiliation":[{"name":"Technical University of Darmstadt, Secure Mobile Networking Lab"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"article-title":"A walk with Shannon","year":"2018","author":"cama","key":"ref13"},{"year":"2020","key":"ref57","article-title":"CC3235S and CC3235SF SimpleLink Wi-Fi, Dual-Band, Single-Chip Solution Datasheet (Rev. B)"},{"year":"2021","key":"ref12","article-title":"Bluetooth Security Notices"},{"key":"ref56","first-page":"37","article-title":"A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct Link","author":"stute","year":"2019","journal-title":"28th USENIX Security Symposium (USENIX Security 19)"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48987.2021.00049"},{"year":"2019","key":"ref59","article-title":"Coexistence Throughput Test"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243802"},{"year":"2018","key":"ref58","article-title":"Overview of SECI"},{"year":"2021","key":"ref53","article-title":"Wi-Fi Coexistence with Other 2.4 GHz Radio Protocols"},{"year":"2020","key":"ref52","article-title":"AN1128: Bluetooth Coexistence with Wi-Fi, Rev. 1.6"},{"year":"2020","key":"ref11","article-title":"Bluetooth Core Specification 5.2"},{"key":"ref55","first-page":"144","article-title":"Improving the Reliability of Bluetooth Low Energy Connections","author":"sp\u00f6rk","year":"2020","journal-title":"EWSN"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/49.840210"},{"key":"ref54","article-title":"Timing Analysis of Keystrokes and Timing Attacks on SSH","author":"song","year":"2001","journal-title":"USENIX Security Symposium"},{"year":"2016","key":"ref17","article-title":"Cypress to Acquire Broadcom&#x2019;s Wireless Internet of Things Business"},{"year":"2020","key":"ref16","article-title":"Security Bulletin: Potential Wi-Fi + Bluetooth Combo Security Vulnerabilities"},{"year":"2018","key":"ref19","article-title":"AN214852 - Collaborative Coexistence Interface Between Cypress-to-Cypress Solutions and Cypress-to- third-party Chips"},{"journal-title":"BCM4339 Single-Chip 5G WiFi IEEE 802 11ac MAC\/Baseband\/Radio with Integrated Bluetooth 4 1 and FM Receiver","year":"2017","key":"ref18"},{"article-title":"Nexmon: The C-based Firmware Patching Framework","year":"2017","author":"schulz","key":"ref51"},{"article-title":"Teaching Your Wireless Card New Tricks: Smartphone Performance and Security Enhancements Through Wi-Fi Firmware Modifications","year":"2018","author":"schulz","key":"ref50"},{"article-title":"CVE 2019&#x2013;11516 PoC","year":"2019","author":"ruge","key":"ref46"},{"year":"2016","key":"ref45","article-title":"QCA6234 Integrated Dual-Band 2x2 8021 1n + Bluetooth 4.0"},{"key":"ref48","article-title":"Frankenstein: Advanced Wireless Fuzzing to Exploit New Bluetooth Escalation Targets","author":"ruge","year":"2020","journal-title":"28th USENIX Security Symposium (USENIX Security 19)"},{"year":"2020","key":"ref47","article-title":"CVE-2020&#x2013;0022 an Android 8.0&#x2013;9.0 Bluetooth Zero-Click RCE &#x2013; BlueFrag"},{"year":"2016","key":"ref42","article-title":"MT7632U Datasheet"},{"article-title":"Exploring the MediaTek Baseband","year":"2020","author":"grassi","key":"ref41"},{"year":"2020","key":"ref44","article-title":"PAN9026 Wi-Fi\/BT Module with Marvell 88W8977 WLAN 2.4\/5 GHz and Bluetooth single-chip solution inside (Rev 1.2)"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3395351.3399351"},{"year":"2021","author":"r\u00f6ttger","key":"ref49"},{"article-title":"An iOS zero-click radio proximity exploit odyssey","year":"2020","author":"beer","key":"ref8"},{"year":"2020","key":"ref7","article-title":"RT-AC86U Source Code"},{"article-title":"Over The Air: Exploiting Broadcom&#x2019;s Wi-Fi Stack (Part 1)","year":"2017","author":"beniamini","key":"ref9"},{"year":"0","key":"ref4","article-title":"Profiles and Logs - Bug Reporting - Apple Developer"},{"year":"2021","key":"ref3","article-title":"Gabeldorsche Bluetooth Stack"},{"article-title":"Broadpwn: Remotely Compromising Android and iOS via a Bug in Broadcom&#x2019;s Wi-Fi Chipsets","year":"2017","author":"artenstein","key":"ref6"},{"year":"2020","key":"ref5","article-title":"Privacy-Preserving Contact Tracing"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3307334.3326089"},{"key":"ref35","article-title":"How To Tame Your Unicorn - Exploring and Exploiting Zero-Click Remote Interfaces of Modern Huawei Smartphones","author":"komaromy","year":"2021","journal-title":"BlackHat USA 2021"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00002"},{"article-title":"LTE and Bluetooth In-Device Coexistence with WLAN. Application Note","year":"0","author":"liebl","key":"ref37"},{"key":"ref36","article-title":"Finding New Bluetooth Low Energy Exploits via Reverse Engineering Multiple Vendors&#x2019; Firmwares","author":"kovah","year":"2020","journal-title":"BlackHat USA 2020"},{"year":"2004","key":"ref31","article-title":"IEEE 802.11i-2004: Amendment 6: Medium Access Control (MAC) Security Enhancements"},{"key":"ref30","article-title":"Emulating Samsung&#x2019;s Baseband for Security Testing","author":"hernandez","year":"2020","journal-title":"BlackHat USA 2020"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/2678373.2665726"},{"year":"2020","key":"ref32","article-title":"Intel Wireless-AC 9560 Product Brief"},{"key":"ref2","article-title":"BLUR-tooth: Exploiting Cross-Transport Key Derivation in Bluetooth Classic and Bluetooth Low Energy","author":"antonioli","year":"2020","journal-title":"arXiv preprint arXiv 2009 11189"},{"article-title":"Reverse-engineering Broadcom Wireless Chipsets","year":"2019","author":"anguelkov","key":"ref1"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3395351.3399360"},{"key":"ref38","article-title":"Meltdown","author":"lipp","year":"2018","journal-title":"arXiv org E-Print Archive"},{"key":"ref24","first-page":"911","article-title":"SweynTooth: Unleashing Mayhem over Bluetooth Low Energy","author":"garbelini","year":"2020","journal-title":"2020 USENIX Annual Technical Conference (USENIX ATC)"},{"article-title":"BrakTooth: Causing Havoc on Bluetooth Link Manager","year":"2021","author":"garbelini","key":"ref23"},{"key":"ref26","article-title":"Exploiting Qualcomm WLAN and Modem Over The Air","author":"gong","year":"2019","journal-title":"DEF CON 27"},{"article-title":"There&#x2019;s Life in the Old Dog Yet: Tearing New Holes into Intel\/iPhone Cellular Modems","year":"2018","author":"golde","key":"ref25"},{"year":"2021","key":"ref20","article-title":"WICED Software"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN.2007.4317845"},{"key":"ref22","article-title":"Polypyus&#x2013; the firmware historian","author":"friebertsh\u00e4user","year":"2020","journal-title":"Workshop on Binary Analysis Research (BAR) 2021"},{"year":"2021","key":"ref21","article-title":"owfuzz"},{"key":"ref28","doi-asserted-by":"crossref","first-page":"300","DOI":"10.1007\/978-3-319-40667-1_15","article-title":"Rowhammer.js: A remote software-induced fault attack in JavaScript","author":"gruss","year":"2016","journal-title":"Detection of Intrusions and Malware and Vulnerability Assessment"},{"key":"ref27","article-title":"Over the Air Baseband Exploit: Gaining Remote Code Execution on 5G Smartphones","author":"grassi","year":"2021","journal-title":"BlackHat USA 2021"},{"journal-title":"ReCon","article-title":"Burned in Ashes: Baseband Fairy Tale Stories","year":"2019","key":"ref29"},{"key":"ref60","article-title":"Dive into Apple IO80211FamilyV2","author":"wang","year":"2020","journal-title":"BlackHat USA 2020"},{"key":"ref62","first-page":"135","author":"xiao","year":"2009","journal-title":"Overview of IEEE 802 15 2 Coexistence of Wireless Personal Area Networks with Other Unlicensed Frequency Bands Operating Wireless Devices"},{"key":"ref61","first-page":"339","article-title":"LightBlue: Automatic Profile-Aware Debloating of Bluetooth Stacks","author":"wu","year":"2021","journal-title":"30th USENIX Security Symposium (USENIX Security 21)"}],"event":{"name":"2022 IEEE Symposium on Security and Privacy (SP)","start":{"date-parts":[[2022,5,22]]},"location":"San Francisco, CA, USA","end":{"date-parts":[[2022,5,26]]}},"container-title":["2022 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9833550\/9833558\/09833639.pdf?arnumber=9833639","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,8]],"date-time":"2023-11-08T23:07:12Z","timestamp":1699484832000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9833639\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5]]},"references-count":63,"URL":"https:\/\/doi.org\/10.1109\/sp46214.2022.9833639","relation":{},"subject":[],"published":{"date-parts":[[2022,5]]}}}