Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bluejacking is unsolicited messaging; bluesnarfing is covert data theft; bluebugging is unauthorized control of a vulnerable device. The labels describe different threats, and the classic examples in NIST’s guidance center on older devices and firmware—not proof that these attacks are common against patched phones today. Bluetooth security still matters, but vivid names are not a measure of present-day risk.

What is bluejacking vs. bluesnarfing vs. bluebugging?

The names are easy to confuse, but the attacks differ in what they do and what an attacker can gain. The National Institute of Standards and Technology (NIST) describes bluejacking as sending unsolicited messages to Bluetooth-enabled mobile devices. The message itself does not damage the device; the danger is that a recipient might respond or add a contact, turning the encounter into something like spam or phishing.

Attack What it does User interaction Primary target and consequence Historical context
Bluejacking Sends an unsolicited message to a Bluetooth-enabled device. The unsolicited message does not itself require a response. A user may be enticed to reply or add a contact. Messages or contacts; chiefly a nuisance or a route to social engineering, rather than device damage from the message alone. NIST defines the behavior in its 2022 Bluetooth security guide.
Bluesnarfing Exploits flaws to obtain data from a target device without the user’s knowledge or interaction. Not required in the NIST Mobile Threat Catalogue’s description. Stored data, including information such as an IMEI; the consequence is data exposure. NIST’s guide describes exploitation of firmware flaws in older devices.
Bluebugging Exploits flaws to issue commands to a target device without informing its user. Not required in NIST’s description. Device functions and data: the attacker may access information, place calls, eavesdrop on calls, send messages, or use other services. NIST’s catalogue characterizes the outcome as full control of a vulnerable device. NIST’s guide likewise emphasizes flaws in older firmware.

The comparison draws on NIST SP 800-121 Rev. 2 (2022) and the NIST Mobile Threat Catalogue entries LPN-9 (bluesnarfing) and LPN-10 (bluebugging). The terms describe different levels of impact: an unwanted message, covert access to data, and unauthorized device commands.

Can someone hack your phone through Bluetooth?

Bluetooth is short-range wireless communication, so these named attacks are not remote-internet compromises by default: an attacker generally needs to be within Bluetooth communication range. That does not make every nearby device vulnerable. Bluesnarfing and bluebugging, as described in NIST’s guide, depend on flaws associated with older device firmware. Whether a specific phone is exposed depends on its software, configuration, and the vulnerability involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Bluejacking is also not equivalent to taking over a phone. An unsolicited message is not, by itself, evidence that the sender has accessed the recipient’s data or gained control of the device.

Is Bluetooth still vulnerable?

Bluetooth security remains an active engineering concern, but that fact should not be confused with proof that the classic bluejacking, bluesnarfing, or bluebugging scenarios are widespread on current, patched devices. NIST SP 800-121 Rev. 2, published in 2022, covers Bluetooth versions 1.1 through 4.2 and offers security recommendations; it is a dated guide, not a complete account of every later Bluetooth implementation.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

As one example of ongoing vulnerability tracking, the National Vulnerability Database records CVE-2023-24023 with a CISA-ADP CVSS 3.1 base score of 6.4 (medium). That record shows that Bluetooth-related issues continue to be documented; it does not establish that the issue is one of these three historically named attacks, nor that those attacks are common on patched modern phones.

The perception question deserves the same care. Vivid labels can make older attacks sound like a current everyday threat, but there is no authoritative published statistic here measuring how many people believe they are vulnerable to these three attacks. Their memorable names are not evidence of a measured public trend.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Thetis Security Key - U2F and FIDO2, USB A, Two Factor Authenticator with Bluetooth, Multi-Layered Authentication Protection HOTP U2F Compatible Windows, MacOS, Gmail, Linux - Black
  • Mobile Bluetooth Compatibility - Connect to various iPhone or Android devices using advanced Bluetooth Low Energy Technology. Plus, NFC with iOS, and Android devices. Protection to prevent hacking, theft, scams, phishing, etc.
  • No More Passwords - Revolutionizing the future of online security and account protection by being backed by FIDO2 protocol technology and the world’s largest standard-based, interoperable authentication processes. An effortless password-less world now awaits. **Note: FIDO2 does not support Mac log-in.
  • Keep Online Account Safe - All our FIDO2 keys are backward compatible with U2F protocols and coincide with the latest Chrome browser and other popular operating systems including: Windows, macOS, and even Linux. U2F is supported and protected on all websites that follow U2F protocols. Note: Only Enterprise Users using Azure Active Directory can access Windows Hello log-in via Thetis FIDO2 BLE Security Key.
  • Multi-Step Authentication - Designed with advanced HOTP (One Time Password) technology that offers an intricate and personalized multi-factored authentication process.
  • Sleek & Durable Design - A sleek and slim black frame with a full 360 rotating aluminum alloy cover that protects the USB connector during non-use. Durable, reliable, and sturdy alloy protects the Thetis Key from daily use, accidental drops, and minor scratches. Thetis are proud to offer our customers a full 1-Year Warranty.

How do you reduce the risk of Bluetooth attacks?

NIST’s explicit countermeasure in the Mobile Threat Catalogue is to disable Bluetooth on vulnerable devices. The following steps separate that stronger exposure reduction from ordinary device-maintenance practices:

  1. Turn Bluetooth off when you are not using it, especially on older or otherwise vulnerable devices. This is the catalogue’s stated countermeasure for bluesnarfing and bluebugging.
  2. If Bluetooth needs to stay enabled, reduce nearby exposure. NIST’s catalogue says operating away from windows and doors lowers the probability that a nearby attacker can establish communication.
  3. Keep the device operating system, Bluetooth firmware, and applications updated. Treat updates as standard security hygiene; the catalogue’s specific stated countermeasure remains disabling Bluetooth on vulnerable devices.
  4. Be cautious with unsolicited messages and contact requests. A bluejacking message alone does not harm the device, but replying or adding an unknown contact can open the door to spam or phishing.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does turning Bluetooth off prevent bluebugging?

Turning Bluetooth off prevents an attacker from using that Bluetooth connection while it is disabled, which is why NIST recommends disabling it on vulnerable devices. It is not a general fix for unrelated ways a device could be attacked, and it does not repair a firmware flaw. When Bluetooth is needed, keep the device updated and limit exposure in the ways described above.

Rank #4
Sale
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.