CPE
ESP32-audioI2S versions 3.4.4 through 4.0.0 are susceptible to a heap-based out-of-bounds read vulnerability in the ID3 header parsing logic that could lead to memory disclosure or device instability.