PT-2026-23778 · Philips · Philips Hue Bridge
Xilokar
·
Published
2026-03-06
·
Updated
2026-04-27
·
CVE-2026-3560
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Philips Hue Bridge (affected versions not specified)
Description
A heap-based buffer overflow exists in the HomeKit component of the Philips Hue Bridge, specifically within the
hk hap pair storage put function. This issue could allow for remote code execution. The vulnerability was discovered during the Pwn2Own competition.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Philips Hue Bridge