CVE-2026-28527 is an out-of-bounds read vulnerability affecting BlueKitchen BTstack versions prior to 1.8.1, specifically within the AVRCP Controller GET_PLAYER_APPLICATION_SETTING_ATTRIBUTE_TEXT and GET_PLAYER_APPLICATION_SETTING_VALUE_TEXT handlers. Attackers can exploit this by establishing a paired Bluetooth Classic connection and sending specially crafted VENDOR_DEPENDENT responses. This allows for reading beyond packet boundaries, leading to information disclosure and potential device crashes, with a CVSS score of 7.3 (HIGH). Currently, there is no evidence of active exploitation, nor is public exploit code available on platforms like Metasploit or ExploitDB, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.1CPE matchmatch criteria | cpe:2.3:a:bluekitchen-gmbh:btstack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.