Impact
The vulnerability is a buffer overflow in the Bluetooth host stack caused by copying data into a buffer without checking the size of the input when processing registry values with incorrect types using a direct query method. This memory corruption can overwrite adjacent memory and may allow an attacker to execute arbitrary code, thereby compromising confidentiality, integrity, and availability. The flaw is a classic instance of CWE‑120.
Affected Systems
Qualcomm, Inc. Snapdragon is the only vendor listed, and no specific firmware or operating system versions have been disclosed. As a result, all Snapdragon devices that implement the affected Bluetooth host stack are potentially vulnerable, but the exact scope cannot be precisely determined without version information.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate‑to‑high severity. EPSS is not available, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploits yet. The likely attack vector involves an attacker sending a crafted Bluetooth registry request that triggers the unsafe copy, which could be possible from a local or over‑the‑air connection depending on the device’s exposure. Mitigation focuses on patching or disabling vulnerable Bluetooth functionality to prevent exploitation.
OpenCVE Enrichment