Tarlogic Security has detected a backdoor in the ESP32, a microcontroller that enables WiFi and Bluetooth connection and is present in millions of mass-market IoT devices. Exploitation of this backdoor would allow hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls.
The ESP32 chip, developed by Espressif Systems, is widely used in various IoT (Internet of Things), embedded systems, and consumer electronics due to its low power consumption, built-in Wi-Fi & Bluetooth, and high processing capability.
Devices That Use the ESP32 Chip
Development Boards & Microcontrollers
ESP32 DevKit series (official Espressif boards)
M5Stack and M5Stick series
Adafruit HUZZAH32
SparkFun ESP32 Thing
LilyGO T-Series (T-Display, T-SIM, T-Watch, etc.)
WEMOS Lolin D32/D32 Pro
Smart Home & IoT Devices
Sonoff Smart Switches and Plugs (e.g., Sonoff Mini R3, Sonoff S31)
Shelly Smart Relays (e.g., Shelly 1, Shelly 2.5)
Tuya-Based Smart Devices (many smart home products use Tuya firmware on ESP32)
Air quality monitors (e.g., AirGradient open-source air sensors)
IoT Sensor Hubs (various DIY and commercial solutions)
Wearables & Portable Devices
TTGO T-Watch (ESP32-based smartwatch)
Heltec WiFi Kit Series (LoRa-enabled IoT devices)
Fitness trackers (some DIY and prototype models)
Robotics & DIY Electronics
ESP32-CAM (ESP32-based camera module)
DIY drones & robots (used in hobbyist and educational robotics)
3D Printer controllers (e.g., ESP32-based Klipper controllers)
Energy monitoring devices (e.g., OpenEnergyMonitor)
Smart locks & security systems
Audio & Multimedia Devices
ESP32-based web radios
DIY Bluetooth speakers
Smart light controllers with voice assistants
Why Is ESP32 Popular?
✔ Low-cost & powerful (dual-core, Wi-Fi, Bluetooth)
✔ Great for DIY & commercial IoT applications
✔ Strong developer community & open-source support
✔ Compatible with Arduino, MicroPython, ESP-IDF, etc.