Memory Corruption Vulnerability in ArduinoBLE Bluetooth Low Energy Implementation
CVE-2026-47773
7.2HIGH
What is CVE-2026-47773?
The ArduinoBLE library, facilitating Bluetooth Low Energy (BLE) connections on select Arduino models, suffers from a memory corruption issue due to insufficient bounds checking in the ATT layer's write request handler. This vulnerability permits a remote, unauthenticated BLE client to corrupt memory associated with the ATTClass global object, adversely impacting the device's functionality. Specifically, devices utilizing ArduinoBLE with one or more characteristics configured with the BLEEncryption property are at risk. Users are advised to update to version 2.0.2 or later to mitigate this vulnerability.
Affected Version(s)
ArduinoBLE < 2.0.2
