An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the application's client-side chat censor filter.
No PoCs from references.
- https://github.com/actuator/7-Eleven-Bluetooth-Smart-Cup-Jailbreak
- https://github.com/actuator/cve
- https://github.com/nomi-sec/PoC-in-GitHub