The fact that paired devices are able to arbitrarily change their profile long after pairing seems to be the real issue here, and probably what was patched in yesterday's iOS/macOS releases.
There is nothing on this in the security notes to these updates, but my guess is that the CVEs will be disclosed in a bit.
Comments
That's what I thought too, but it seems like FIDO CTAP over BLE is its own thing and does not use Bluetooth HID: https://fidoalliance.org/specs/fido-v2.0-id-20180227/fido-cl...
The fact that paired devices are able to arbitrarily change their profile long after pairing seems to be the real issue here, and probably what was patched in yesterday's iOS/macOS releases.
There is nothing on this in the security notes to these updates, but my guess is that the CVEs will be disclosed in a bit.