Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Google Android
Details
CVSS v3
5.3
NVD published
2025-09-12 17:15:45
EPSS
0.1% probability · 32.6th percentile — 2026-03-20
Affected versions
cpe:2.3:a:opensynergy:blue_sdk:*:*:*:*:*:*:*:*
Summary
OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Improper Input Validation. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper validation of remote L2CAP channel ID (CID). An attacker can leverage this to create an L2CAP channel with the null identifier assigned as a remote CID.
TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.