CVE-2026-28526 identifies an out-of-bounds read vulnerability in BlueKitchen BTstack versions prior to 1.8.1, specifically affecting the AVRCP Controller's LIST_PLAYER_APPLICATION_SETTING_ATTRIBUTES and LIST_PLAYER_APPLICATION_SETTING_VALUES handlers. A nearby attacker with an established Bluetooth Classic connection can exploit this by sending a specially crafted VENDOR_DEPENDENT response. This low-complexity attack (CVSS 3.5) could lead to an out-of-bounds read from the L2CAP receive buffer, potentially causing a denial of service on resource-constrained devices. There is currently no evidence of active exploitation, nor are public exploit codes available, with only minimal community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.1CPE matchmatch criteria | cpe:2.3:a:bluekitchen-gmbh:btstack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.