CVE-2025-23050: Qt
Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
Affected products
- Qt Qt: before 5.15.19 (fixed in 5.15.19); from 6.0.0, before 6.5.9 (fixed in 6.5.9); from 6.6.0, before 6.8.2 (fixed in 6.8.2)
Published 2025-10-31. Last modified 2026-06-17.