Clarification on Alleged ESP32 Backdoor
2025-03-11

Recent media reports claimed an ESP32 chip backdoor. Espressif clarifies that the reported functionality is internal debug commands for testing, not remotely accessible via Bluetooth, radio, or internet. These commands pose no security risk by themselves, though Espressif will provide a software fix to remove them. Only ESP32 chips are affected; ESP32-C, ESP32-S, and ESP32-H series are not. Espressif thanks the security researchers for their responsible disclosure.
Hardware