Nullcon Goa

Unauthenticated Pre Pairing Gatt Write Vulnerability In Smartwatch Ecosystems

37:27 · 28 Feb 2026 – 01 Mar 2026 · YouTube

About this talk

This talk explores the vulnerabilities in budget smartwatches in India's consumer market, focusing on the GATT characteristics that allow unauthenticated writes over unsecured connections. The speakers, Gurjot Singh, Vipin Venu, and Arjun V of Innspark Solutions, discuss how the reverse engineering of OEM firmware can enable attackers to spoof calls, inject notifications, trigger alarms, and reset devices without user consent. They also explain why the Unauthenticated Pre-Pairing GATT Write vulnerability poses a significant risk, affecting approximately 70% of smartwatches in India, and present solutions for secure-by-design implementations that could mitigate these risks.

From event

Nullcon Goa

28 Feb 2026 – 01 Mar 2026

All event videos
Back to Watch