Skip to finding
important · Bluetooth — Zephyr

An unauthenticated Bluetooth Classic peer can inject data into Zephyr L2CAP handlers before authentication completes.

Affects

Zephyr, an embedded real-time operating system used in connected devices

While a dynamic channel is still half-open, Zephyr can resolve its destination CID and dispatch attacker-controlled data without requiring the CONNECTED state.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 11, 2026