Bluetooth Stack Vulnerability in Volkswagen MIB3 Infotainment Systems
CVE-2023-28911
Key Information:
- Vendor
- CVE Published:
- 28 June 2025
What is CVE-2023-28911?
A vulnerability exists within the Bluetooth stack of Volkswagen's MIB3 infotainment systems, stemming from the insufficient validation of user-supplied data. This flaw can lead to arbitrary channel disconnections, enabling attackers to execute denial-of-service (DoS) attacks against all connected clients of the infotainment device. The vulnerability was initially identified in the Skoda Superb III vehicle featuring the MIB3 unit with OEM part number 3V0035820, with additional affected models and OEM part numbers available in the referenced security advisories.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Volkswagen MIB3 infotainment system MIB3 OI MQB 0 <= 0304
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
