-I'd be surprised if some unknown exploit was being used to gain access to Bluetooth - basically, it would probably be too useful for other, more nefarious purposes, so it would be unlikely to be used in an app deployed to millions.
The Norwegian NHS equivalent had a similar app developed, running off-screen on both Android and iOS, using Bluetooth - though I have no idea how they pull it off.
Edit: The above paragraph is incorrect; my apologies. I did some research and found that the app only uses Bluetooth on iOS when the phone is unlocked; however the app itself may be off-screen.
While the phone is locked, it relies on GPS for positioning and presumably correlates location and time data to indicate whether you may have been exposed to an infected person or not.
Irrelevant anecdote - as I am typing this, Spotify put on The The's 80s hit 'Infected'. Hah!
Germany turned on a dime, and is going to use the Google/Apple solution. Denmark is about to turn on the same dime, as our solution mirrored the Norwegian solution, but had the same iOS problems (I only read that the government was strongly considering the Google/Apple solution, but no verdict yet).
The Norwegian NHS equivalent had a similar app developed, running off-screen on both Android and iOS, using Bluetooth - though I have no idea how they pull it off.
Edit: The above paragraph is incorrect; my apologies. I did some research and found that the app only uses Bluetooth on iOS when the phone is unlocked; however the app itself may be off-screen.
While the phone is locked, it relies on GPS for positioning and presumably correlates location and time data to indicate whether you may have been exposed to an infected person or not.
Irrelevant anecdote - as I am typing this, Spotify put on The The's 80s hit 'Infected'. Hah!