Out-of-bounds read in ESP-IDF - CVE-2026-81508
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose limited heap contents.
The vulnerability exists due to an out-of-bounds read in the Bluedroid A2DP sink media-packet handler (btc_a2dp_sink_handle_inc_media) when processing malformed A2DP media packets. A remote attacker can send a malformed media packet to read adjacent heap memory.
Only builds with BlueDroid Classic Bluetooth and A2DP sink support enabled are affected.