{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aesp32-audioi2s_projectesp32-audioi2s/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:esp32-audioi2s_project:esp32-audioi2s:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-87961"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ESP32-audioI2S (3.4.4-4.0.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ESP32-audioI2S"],"content_html":"\u003cp\u003eESP32-audioI2S versions 3.4.4 through 4.0.0 contain a heap-based out-of-bounds read vulnerability in the read_ID3_Header function. The flaw exists due to a shadowed length parameter encountered during the processing of ID3 synchronized-lyrics tags. An attacker can trigger this condition by supplying a malicious MP3 file or a network-delivered HTTP audio stream containing oversized frame size declarations. When the affected library attempts to parse these malformed ID3 tags, it reads beyond the bounds of the allocated heap buffer. Successful exploitation of this vulnerability may result in device crashes (denial of service) or the unauthorized exposure of sensitive data residing in adjacent memory locations. Because this library is commonly used in embedded IoT audio projects, the potential impact involves remote exploitation of internet-connected sound systems and media hardware.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-87961 leads to denial-of-service via device crash or unauthorized disclosure of adjacent heap memory. Impact is concentrated in IoT environments using ESP32 hardware for audio processing, where devices may be exposed to remote network streams or untrusted file input.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the ESP32-audioI2S library to a version beyond 4.0.0 that contains the patch for the read_ID3_Header function.\u003c/li\u003e\n\u003cli\u003eIn environments where immediate patching is not possible, sanitize input audio streams and file uploads to validate ID3 frame size declarations against maximum expected buffer limits.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation for IoT devices to restrict access to untrusted HTTP audio sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T15:08:21Z","date_published":"2026-09-10T15:08:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-esp32-audioi2s-oob-read/","summary":"ESP32-audioI2S versions 3.4.4 through 4.0.0 are susceptible to a heap-based out-of-bounds read vulnerability in the ID3 header parsing logic that could lead to memory disclosure or device instability.","title":"Heap-based Out-of-Bounds Read in ESP32-audioI2S","url":"https://feed.craftedsignal.io/briefs/2026-09-esp32-audioi2s-oob-read/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:esp32-Audioi2s_project:esp32-Audioi2s:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}