Junglewise Threat Intelligence

CVE-2026-79379: Bestechnic BES2300 buffer overflow in SBC_DecodeFrames

CVE-2026-79379 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Bestechnic's BES2300 is a Bluetooth audio processor chip used in wireless headphones, speakers, and hearing aids. A buffer overflow vulnerability in its firmware allows attackers to crash the device remotely by sending a specially crafted audio frame, causing the device to stop working until restarted.

Technical details

A buffer overflow exists in the SBC_DecodeFrames() function within the Bluetooth audio decoding logic of BES2300 firmware versions 3.x and earlier. The vulnerability is triggered when processing a malformed SBC (Subband Coding) audio frame, allowing an attacker with Bluetooth network access to send a crafted frame that overflows a buffer in the codec's decode path. The attack requires only Bluetooth proximity and no authentication. An attacker can achieve denial of service by repeatedly crashing the audio processing function. The vulnerability is fixed in firmware version 5.0.

Affected products

  • Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC v3.x and earlier (fixed in v5.0)

Timeline

  • 2026-09-08: disclosed

References