CVE-2026-28527: BlueKitchen BTstack < 1.8.1 AVRCP Controller GET_PLAYER_APPLICATION_SETTING_*_TEXT Handlers OOB Read
BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GETPLAYERAPPLICATIONSETTINGATTRIBUTETEXT and GETPLAYERAPPLICATIONSETTINGVALUETEXT handlers that allows nearby attackers to read beyond packet boundaries. Attackers can establish a paired Bluetooth Classic connection and send specially crafted VENDORDEPENDENT responses to trigger out-of-bounds reads, causing information disclosure and potential crashes on affected devices.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BlueKitchen BTstackto a version that resolves this vulnerability.Fixed in 1.8.1 - Compensating control
Limit exposure to nearby Bluetooth Classic attackers by reducing Bluetooth Classic availability/accepting paired connections only when needed (paired Bluetooth Classic connection is required for the described exploit).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28527?
CVE-2026-28527 is classified as a medium severity vulnerability.
How do I fix CVE-2026-28527?
To fix CVE-2026-28527, upgrade BlueKitchen BTstack to version 1.8.1 or later.
What types of vulnerabilities does CVE-2026-28527 involve?
CVE-2026-28527 involves an out-of-bounds read vulnerability affecting AVRCP Controller handlers.
Which versions of BlueKitchen BTstack are affected by CVE-2026-28527?
Versions of BlueKitchen BTstack prior to 1.8.1 are affected by CVE-2026-28527.
What impact does CVE-2026-28527 have on systems?
CVE-2026-28527 may allow unauthorized access to sensitive data due to the out-of-bounds read.