Impact
An out‑of‑bounds read in Qt NFC's language code length parser allows a physically proximate attacker to read memory between a bounded and an unbounded length, potentially revealing data and triggering a denial of service. The vulnerability, classified as CWE‑125 and CWE‑191, corrupts program state or exposes data but does not permit arbitrary code execution.
Affected Systems
Qt’s NFC module is affected, specifically the QNdefNfcTextRecord handling within the Qt Qt library. Version information is not specified in the CVE vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates medium to high severity. EPSS information is not available and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation yet. The attack likely requires an attacker to present a crafted NFC tag to a device that actively scans NFC tags, meaning physical proximity is necessary to cause a denial of service or disclose limited memory.
OpenCVE Enrichment