logo

Using RF Power Levels to Defeat MAC Address Randomization Enabling Passive Device Tracking

ID: f98440bc-92b9-5935-8fde-34ad40571c73

STIX ID: report--f98440bc-92b9-5935-8fde-34ad40571c73

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
30/100

Date Published: 2026-03-31

Date Updated: 2026-04-28

Author: Tom Neaves

...
...

This report presents a proof-of-concept showing that passive correlation of RSSI (signal power) and timing can link randomized MAC addresses in BLE devices across rotation events, enabling persistent tracking despite MAC randomization. The author describes scanning methodology, observed signal behavior when devices appear/disappear, real-world data confirming the technique, and suggests software mitigations (e.g., manipulating signal characteristics at rotation) to reduce the privacy risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.