Impact
A malformed Bluetooth A2DP media packet can trigger an out‑of‑bounds read of a timestamp field before the packet layout is validated. The read exposes adjacent heap memory, allowing an attacker to gain limited visibility of heap contents. No arbitrary memory disclosure or code execution has been demonstrated.
Affected Systems
Espressif ESP-IDF versions 5.5.5, 6.0.1, and 6.1 when compiled with BlueDroid Classic Bluetooth and A2DP sink support are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates the flaw is of moderate risk. An attacker must have paired with the target device and be within radio range to send a malformed packet. Because the vulnerability causes only a bounded read, exploitation is limited to disclosure of portions of heap memory; there is no known path to arbitrary code execution. The EPSS score is not available and the vulnerability is not listed in CISA KEV. The risk of exploitation is considered low, but the presence of the vulnerable code path remains an opportunity for an attacker with local pairing to gather sensitive data.
OpenCVE Enrichment