CVE-2026-87961: ESP32-audioI2S 3.4.4 through 4.0.0 Heap-based Out-of-Bounds Read via Shadowed Length Parameter in read_ID3_Header

Published Sep 10, 2026
·
Updated

ESP32-audioI2S versions 3.4.4 through 4.0.0 contain a heap-based out-of-bounds read vulnerability in the readID3Header function due to a shadowed length parameter in ID3 synchronized-lyrics processing. Attackers can craft malicious MP3 files or HTTP audio streams with oversized frame size declarations to read past allocated buffer boundaries, causing device crashes or exposing adjacent heap memory.

Affected Software

1 affected component
ESP32-audioI2S>=3.4.4<=4.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ESP32-audioI2S to a version that resolves this vulnerability.

    Fixed in 4.0.0

Event History

Sep 10, 2026
CVE Published
via MITRE·10:52 AM
Data Sourced
via MITRE·10:52 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What input paths can trigger the issue?

The vulnerable parsing path can be reached through a crafted MP3 file or an HTTP audio stream containing oversized frame size declarations in ID3 synchronized-lyrics data.

2

What does an attacker need to exploit this?

The vector is network-accessible and requires low attack complexity, no privileges, but user interaction is required. The attacker needs the target to process the malicious MP3 content or stream.

3

What are the likely effects on an affected device?

Processing the malicious content can read beyond an allocated heap buffer, which may crash the device or expose adjacent heap memory. The stated impact is low confidentiality impact and high availability impact.

4

Which releases are affected?

ESP32-audioI2S versions 3.4.4 through 4.0.0 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203