Junglewise Threat Intelligence

CVE-2026-68849: Microsoft Windows Bluetooth Port Driver out-of-bounds read

CVE-2026-68849 · Severity: medium · CVSS 4.7 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Bluetooth Port Driver, a core component managing Bluetooth device communication on Windows systems, contains an out-of-bounds read vulnerability. An authorized local user could exploit this flaw to read sensitive information from system memory, potentially disclosing configuration data or other confidential details.

Technical details

The vulnerability is an out-of-bounds read in the Windows Bluetooth Port Driver that allows an authorized local attacker to access memory outside the intended bounds. The flaw requires local access and authorization privileges to exploit. A successful attack enables information disclosure from kernel or driver memory, potentially revealing sensitive system data. Microsoft has released a security update addressing this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats