

I don’t think is is a backdoor. At the moment I wouldn’t consider this article any more than FUD.
It’s unclear to me if the security company has actually said what the vuln is or not, but if it’s what was presented in the slides linked in the article this is at worst something that can be “attacked” from a computer connected via USB (and I’m pretty sure it would require special software too), where the attack is sending out possibly invalid bluetooth messages to try to attack other devices or flashing new firmware to the ESP itself. It’s not a general “backdoor” in the ESP32 itself. At least that’s the best interpretation I’ve been able to make. Happy to be corrected if anyone finds more info.
Have they said that recently? The only definitive comment I remember from them was something along the lines “definitely not in the next 2-3 years” around launch, which was 3 years ago.
Not saying that means I “expect” it’s happening, just curious if you know of anything more recent that says its not happening.