Philips · Philips Hue Bridge · CVE-2026-3560
**Name of the Vulnerable Software and Affected Versions**
Philips Hue Bridge (affected versions not specified)
**Description**
A heap-based buffer overflow exists in the HomeKit component of the Philips Hue Bridge, specifically within the `hk hap pair storage put` function. This issue could allow for remote code execution. The vulnerability was discovered during the Pwn2Own competition.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.