Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes

Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes

Bloodied (but not broken) by the ordeal, I achieved my goals and stretch goals. And given that there are no public descriptions of how Realtek Bluetooth chips work, I look forward to sharing hitherto-unknown information about how to navigate and understand these mostly-16-bit-MIPS-code systems. And I’ll discuss how their ROM-“patch”ing firmware update mechanism works, how you can patch it to change its code too, and the security implications thereof.