CVE-2026-3560 is a high-severity heap-based buffer overflow vulnerability affecting the Philips Hue Bridge HomeKit implementation. This flaw, residing in the hk_hap_pair_storage_put function, allows unauthenticated, network-adjacent attackers to achieve remote code execution due to improper input validation, resulting in a CVSS score of 8.8. An attacker can leverage this to execute arbitrary code on the device, compromising confidentiality, integrity, and availability. While there is no public exploit code available and it is not currently listed on CISA's KEV catalog, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1975170000CPE matchmatch criteria | cpe:2.3:o:philips:hue_bridge_v2_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.