Out-of-Bounds Read in Qt QLowEnergyController Affecting Bluetooth Functionality
CVE-2025-23050

3.1LOW

Key Information:

Vendor

Qt

Status
Vendor
CVE Published:
31 October 2025

What is CVE-2025-23050?

In the QLowEnergyController component of Qt prior to version 6.8.2, a flaw exists that mishandles malformed Bluetooth ATT commands. This issue can lead to an out-of-bounds read, which may compromise the application's stability and security. Users should update to version 5.15.19, 6.5.9, or 6.8.2, which contain necessary security patches to mitigate this vulnerability.

Affected Version(s)

Qt 0 < 5.15.19

Qt 6.0.0 < 6.5.9

Qt 6.6.0 < 6.8.2

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-23050 : Out-of-Bounds Read in Qt QLowEnergyController Affecting Bluetooth Functionality