You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
bluetooth vulnerability
About this tag
Bluetooth vulnerabilities on Windows and related platforms are a recurring security concern, with threads covering use-after-free flaws, information disclosure, and privilege escalation in the Windows Bluetooth Service, RFCOMM driver, and Linux kernel. Recent CVEs include CVE-2025-58728, CVE-2025-59290, and CVE-2025-59513, all patched by Microsoft in 2025, as well as older advisories like CVE-2021-1638 and CVE-2024-38123. Discussions emphasize the importance of applying updates promptly, as Bluetooth attack surfaces mix local radio exposure with complex driver and service code. While some vulnerabilities require local access, they can serve as reconnaissance or escalation primitives. The tag also covers cross-platform implications, such as Chrome and Linux Bluetooth bugs, highlighting that Bluetooth security hygiene is essential for endpoint protection.
Google Chrome CVE-2026-11699 is a high-severity use-after-free vulnerability in Chrome’s Bluetooth code on macOS, disclosed in June 2026 and fixed for Mac users in Chrome 149.0.7827.103 after Google’s stable-channel desktop security update. The bug is not the loudest Chrome flaw of the month...
CVE-2026-46056 is a newly published Linux kernel Bluetooth vulnerability, disclosed by kernel.org and added to NVD on May 27, 2026, involving a potential use-after-free in Secure Simple Pairing passkey event handlers. The fix is small, but the lesson is not: Bluetooth remains one of the kernel’s...
A newly cataloged Windows vulnerability, tracked as CVE-2025-59513, affects the Bluetooth RFCOM protocol driver and is described by Microsoft as an information‑disclosure flaw that can allow a local, unauthorized actor to obtain sensitive kernel or driver memory when interacting with the RFCOM...
A use-after-free flaw in the Windows Bluetooth Service has been cataloged as CVE-2025-58728 and classified as a local elevation-of-privilege vulnerability that Microsoft patched as part of the October 2025 update cycle; the weakness can allow an authenticated, local user process to corrupt...
A newly cataloged vulnerability, CVE-2025-59290, affects the Windows Bluetooth Service and is described by vendors and trackers as a use‑after‑free (UAF) memory‑corruption flaw that allows an authorized local attacker to elevate privileges on an affected host. A patch was published on October...
On October 8, 2024, Microsoft made an update concerning CVE-2021-1638, which pertains to a Bluetooth security feature bypass vulnerability. This vulnerability has been a point of interest for Windows users, especially those concerned about the security implications of Bluetooth technology within...
Introduction
Mark your calendars: October 8, 2024, just marked a moment of change for those keeping an eye on the ever-evolving landscape of cybersecurity. A seemingly simple update has been issued concerning CVE-2021-1684, a vulnerability affecting Windows Bluetooth features, particularly its...
On August 13, 2024, Microsoft disclosed a significant vulnerability in its Windows Bluetooth driver known as CVE-2024-38123. This vulnerability poses an information disclosure risk, potentially allowing attackers to obtain sensitive information through Bluetooth connections. Understanding this...