Heap-Based Buffer Overflow in BoschSensortec COINES_SDK Affected by Malicious USB/BLE Devices
CVE-2026-42807

8HIGH

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-42807?

A vulnerability in the PC bridge protocol decoder of BoschSensortec COINES_SDK exposes the product to a heap-based buffer overflow. By exploiting this flaw, malicious USB or Bluetooth Low Energy (BLE) devices can send oversized packet lengths, leading to potential denial of service or arbitrary code execution. The decoder fails to validate the bounds of the buffer when forwarding the packet length to the host, allowing unbounded heap overwrites that can corrupt adjacent memory. This issue is present in versions 2.10 to 2.12.2 of the COINES_SDK, making it a significant risk for users with affected devices.

Affected Version(s)

COINES_SDK 2.10 <= 2.12.2

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.