Out-of-Bounds Read Vulnerability in Espressif IoT Development Framework
CVE-2026-81508

4.3MEDIUM

Key Information:

Vendor

Espressif

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-81508?

A vulnerability exists in the Espressif IoT Development Framework (ESP-IDF) affecting versions 5.5.5, 6.0.1, and 6.1. The BlueDroid A2DP sink function, btc_a2dp_sink_handle_inc_media, improperly reads a timestamp from incoming media packets without adequate validation of the packet structure. This flaw allows a paired BR/EDR audio source within range to send malformed A2DP packets, potentially causing out-of-bounds reads into adjacent heap memory. Although this vulnerability can lead to limited disclosure of heap contents, further exploitation such as arbitrary memory disclosure or code execution is not confirmed.

Affected Version(s)

esp-idf = 6.1 = 6.1

esp-idf = 6.0.1 = 6.0.1

esp-idf = 5.5.5 = 5.5.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.