CVE-2026-79377

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of Service (DoS) via sending a crafted L2CAP packet.

Published 2026-09-08. Last modified 2026-09-09.