Skip to finding
important · Bluetooth

An authenticated BLE peer can overwrite adjacent BSS memory through Nordic's glucose-monitoring service.

Affects

Nordic Semiconductor nRF Connect SDK, an embedded SDK used to build Bluetooth Low Energy devices.

The RACP handler copies the full ATT value into a 20-byte static buffer, making the overwritten target dependent on the firmware's BSS layout.

Detail and 3 sources

Affected finished products and an exact fixed release remain unidentified.

Chain to watch
Authenticate to a CGMS-enabled device over BLE→↓Write an oversized value to the Record Access Control Point→↓Overwrite objects adjacent to the 20-byte static buffer→↓The device-specific consequence depends on the linker-assigned BSS layout.
Unverified chainBuild representative affected firmware, inspect linker maps, and replay oversized RACP writes against concrete adjacent objects.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 8, 2026