Blackberry 'reluctantly' admits to QNX flaw
The vulnerability, known as BadAlloc, impacts pre-2012 versions of BlackBerry’s flagship operating system


BlackBerry has "reluctantly" admitted that its QNX operating system (OS) was vulnerable to hacking, and allegedly kept the flaw a secret “for months”.
That's according to a report from Politico, which cited two people familiar with the matter, one of them being a US government employee.
The sources, who were aware of discussions between BlackBerry and US federal cyber security officials, told the publication that the tech giant not only tried to deny the impact of the flaw on its products but also “resisted making a public announcement” about the matter.
The vulnerability, known as BadAlloc, impacts pre-2012 versions of BlackBerry’s flagship QNX software, which are still widely used by an estimated 200 million Volkswagen, BMW, and Ford cars, as well as hospital and factory equipment.
The flaw, which affected multiple different companies including Texas Instruments, NXP, and Google Cloud, was first discovered in late April by Microsoft Security Response Center. At the time, researchers said that they had “not seen any indications of these vulnerabilities being exploited”.
“However, we strongly encourage organisations to patch their systems as soon as possible,” they added. If exploited, BadAlloc would allow hackers to “cripple” IoT and smart devices powered by the OS, potentially risking the lives or safety of hospital patients and car drivers or passengers.
Despite the affected companies coming forward to help resolve the issue in cooperation with the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA), BlackBerry wasn’t involved in the mitigation efforts.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Instead, the company’s representatives denied the impact of the BadAlloc on its products, the anonymous sources told Politico, as CISA “pushed BlackBerry to accept the bad news”.
The company only publicly acknowledged the flaw on Tuesday, issuing a public advisory almost four months after the flaw was discovered and stating that it has notified “all potentially affected customers”.
“BlackBerry has made software patches available to resolve the matter," the company said. "Additionally, BlackBerry is providing 24/7 support to customers as required. At this time no customers have indicated that they have been impacted,” the company announced, adding that “the safety and security of our customers and the public is BlackBerry's top priority”.
BlackBerry didn’t address IT Pro’s request for comment.
Having only graduated from City University in 2019, Sabina has already demonstrated her abilities as a keen writer and effective journalist. Currently a content writer for Drapers, Sabina spent a number of years writing for ITPro, specialising in networking and telecommunications, as well as charting the efforts of technology companies to improve their inclusion and diversity strategies, a topic close to her heart.
Sabina has also held a number of editorial roles at Harper's Bazaar, Cube Collective, and HighClouds.
-
Google faces 'first of its kind' class action for search ads overcharging in UK
News Google faces a "first of its kind" £5 billion lawsuit in the UK over accusations it has a monopoly in digital advertising that allows it to overcharge customers.
By Nicole Kobie
-
Neural interfaces promise to make all tech accessible – it’s not that simple
Column Better consideration of ethics and practical implementation are needed if disabled people are to benefit from neural interfaces
By John Loeppky
-
Hackers are targeting Ivanti VPN users again – here’s what you need to know
News Ivanti has re-patched a security flaw in its Connect Secure VPN appliances that's been exploited by a China-linked espionage group since at least the middle of March.
By Emma Woollacott
-
Broadcom issues urgent alert over three VMware zero-days
News The firm says it has information to suggest all three are being exploited in the wild
By Solomon Klappholz
-
Nakivo backup flaw still present on some systems months after firms’ ‘silent patch’, researchers claim
News Over 200 vulnerable Nakivo backup instances have been identified months after the firm silently patched a security flaw.
By Solomon Klappholz
-
Everything you need to know about the Microsoft Power Pages vulnerability
News A severe Microsoft Power Pages vulnerability has been fixed after cyber criminals were found to have been exploiting unpatched systems in the wild.
By Solomon Klappholz
-
Vulnerability management complexity is leaving enterprises at serious risk
News Fragmented data and siloed processes mean remediation is taking too long
By Emma Woollacott
-
A critical Ivanti flaw is being exploited in the wild – here’s what you need to know
News Cyber criminals are actively exploiting a critical RCE flaw affecting Ivanti Connect Secure appliances
By Solomon Klappholz
-
Researchers claim an AMD security flaw could let hackers access encrypted data
News Using only a $10 test rig, researchers were able to pull off the badRAM attack
By Solomon Klappholz
-
A journey to cyber resilience
whitepaper DORA: Ushering in a new era of cyber security
By ITPro