Super Box Case
The XH9810 is a Bluetooth chip developed by XIHAO Intelligent Technology Co., Ltd..
It is certified as a generic "Bluetooth chip," meaning it is a core component that can be used in various products.
Unlike a consumer-facing product like a smartphone, the XH9810 does not have different "models" for sale to the public. Instead, it is an integrated circuit intended for use by original equipment manufacturers (OEMs) and developers to build their own end products. It is the core component that provides Bluetooth connectivity to those devices.
Other chips in the XIHAO XH98XX series include:
XIHAO Bluetooth chip, XH9810~
XIHAO Bluetooth chip, XH9800~ XIHAO
Bluetooth chip, XH9820~ XIHAO
Bluetooth chip, XH9830~ XIHAO
Bluetooth chip, XH9840~ XIHAO
Bluetooth chip, XH9850~ XIHAO
Bluetooth chip, XH9860~ XIHAO
Bluetooth chip, XH9870~ XIHAO
Bluetooth chip, XH9880~ XIHAO
Bluetooth chip, XH9890~ XIHAO
Bluetooth chip, XH9801~ XIHAO
Bluetooth chip, XH9802~ XIHAO
Bluetooth chip, XH9803~ XIHAO
Bluetooth chip, XH9804~ XIHAO
Bluetooth chip, XH9805~ XIHAO
Bluetooth chip, XH9806~ XIHAO
Bluetooth chip, XH9807~ XIHAO
Bluetooth chip, XH9808~ XIHAO
Bluetooth chip, XH9809~ XIHAO
Bluetooth chip, XH9701-B~ XIHAO
Bluetooth chip, XH9702-B~ XIHAO
Bluetooth chip, XH9703-B~ XIHAO
Bluetooth chip, XH9704-B~ XIHAO
Bluetooth chip, XH9705~ XIHAO
Bluetooth chip, XH9705-B~ XIHAO
Bluetooth chip, XH9706-B~ XIHAO
Bluetooth chip, XH9707-B~ XIHAO
Bluetooth chip, XH9708-B~ XIHAO
Bluetooth chip, XH9709-B
Bluetooth vulnerabilities enable nearby attackers to exploit weaknesses in the wireless communication protocol, allowing them to compromise devices, including smart TVs.
Standard attack methods include:
Botnet recruitment: In 2024, a warning was issued about malware that hijacks Android-based TV boxes, turning them into participants in a botnet. Some of these devices were pre-infected, while others were compromised during the setup process. The malware utilizes the device's internet connection to facilitate fraud and other cybercrimes.
Bluejacking: Sending unsolicited messages, which can contain malicious links to distribute malware or phishing scams.
Bluebugging: Taking control of a device to make calls, send messages, or access data.
Bluesnarfing: Stealing data, such as contacts and emails, from a device.
BlueBorne: A collection of vulnerabilities that allows attackers to take complete control of a device via Bluetooth without user interaction and spread malware to other vulnerable devices.
Key Injection (CVE-2023-45866): A flaw that allows a threat actor to trick a Bluetooth device into pairing with a fake keyboard without user confirmation. On vulnerable smart TVs and Android devices, this can allow an attacker to inject keystrokes and execute arbitrary commands.
Access Control Flaw (CVE-2022-44636): A vulnerability in some Samsung TVs that allows a remote attacker to enable microphone access via Bluetooth spoofing.
