Executive brief
The BES2300 is a Bluetooth audio system-on-chip used in wireless headphones and speakers. A heap overflow vulnerability in its audio decoding component allows an attacker to cause the device to crash or stop responding by sending a specially crafted Bluetooth packet, disrupting service for end users.
Technical details
A heap buffer overflow exists in the a2dp_decoder_sbc.cpp component of Bestechnic BES2300 firmware v3.x and earlier. The vulnerability is triggered when processing SBC (Sub-Band Coding) audio frames over the L2CAP (Logical Link Control and Adaptation Protocol) layer used for Bluetooth audio streaming. An attacker with network proximity (Bluetooth range) can send a crafted L2CAP packet containing malicious audio data to cause heap memory corruption. This results in a denial of service condition via device crash or hang. The vulnerability requires no authentication and affects the audio decoding path that processes incoming Bluetooth audio streams.
Affected products
- Bestechnic BES2300 v3.x and earlier
Timeline
- 2026-09-08: disclosed