Impact
An unauthenticated MESSAGE packet sent via the iOS BitChat application’s mesh gossip cache can trigger a denial of service. The flaw allows a remote actor to repeatedly inject malformed or excessive packets into the cache, exhausting device resources and causing the BitChat service to become unresponsive. This weakness aligns with the category of uncontrolled resource consumption.
Affected Systems
The affected product is BitChat for iOS, version 1.15.0. No other vendor or product information is listed. Devices run the iOS application and are the target of the exploit.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The vulnerability can be exploited over Bluetooth Low Energy by an unauthenticated attacker within communication range. Because authentication is bypassed, any nearby device capable of broadcasting the MESSAGE packet may trigger the denial of service, affecting the target phone’s ability to participate in the BitChat mesh network.
OpenCVE Enrichment