PT-2026-23778 · Philips · Philips Hue Bridge

Xilokar

·

Published

2026-03-06

·

Updated

2026-04-27

·

CVE-2026-3560

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Philips Hue Bridge (affected versions not specified)
Description A heap-based buffer overflow exists in the HomeKit component of the Philips Hue Bridge, specifically within the hk hap pair storage put function. This issue could allow for remote code execution. The vulnerability was discovered during the Pwn2Own competition.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-3560
ZDI-26-158

Affected Products

Philips Hue Bridge