Executive brief
Xbox gaming consoles contain a vulnerability in hardware interface handling that allows a physically present attacker to read sensitive information from the device's memory. An attacker with direct access to the console could potentially extract authentication credentials, user data, or other confidential information stored on the device.
Technical details
An out-of-bounds read vulnerability exists in Xbox hardware interface handling. The vulnerability requires physical access to the device, meaning an attacker must have hands-on access to exploit it. The flaw allows reading memory locations beyond intended boundaries, potentially disclosing sensitive data including credentials, keys, or user information. Physical attack preconditions limit the practical attack surface, but could be relevant in scenarios involving device theft or insider threats.
Affected products
- Microsoft Xbox
Timeline
- 2026-09-08: disclosed