Your HTC mobile phone, when connected using Bluetooth, stands a decent chance of Alberto Moreno Tablado, a security researcher, viewing any sensitive files stored on the device. This is done via the use of a critical bug in some of the HTC's wireless device features. File Transfer Profile (OBEX FTP) service which is built in to the Bluetooth stack implemented by HTC is where the directory traversal flaw resides. Tablado says that it allows attackers to move from a phone's shared folder into other folders. This affects HTC handsets that are running Microsoft Mobile operating system, versions 6 and 6.1.
Link: HTC smartphones vulnerable to Bluetooth file sniffing â