Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory).
https://x.com/pascal_gujer/status/1898442439704158276
https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/
https://reg.rootedcon.com/cfp/schedule/talk/5
https://github.com/TarlogicSecurity/Talks/blob/main/2025_RootedCon_BluetoothTools.pdf
https://flyingpenguin.com/?p=67838
https://cheriot.org/auditing/backdoor/2025/03/09/no-esp32-style-backdoor.html
https://github.com/JasonW88/esp32-cve-2025-27840-power-trace-experiment
https://github.com/demining/Phantom-Signature-Attack
https://github.com/demining/Pixnapping-Attack-on-Android
https://github.com/demining/Digital-Signature-Forgery-Attack
https://github.com/ladyg00se/CVE-2025-27840-WIP
https://github.com/demining/Bluetooth-Attacks-CVE-2025-27840
https://github.com/em0gi/CVE-2025-27840
https://www.espressif.com/en/news/Response_ESP32_Bluetooth
https://news.ycombinator.com/item?id=43308740
https://news.ycombinator.com/item?id=43301369
https://github.com/orgs/espruino/discussions/7699