A vulnerability was found in BlueKitchen BTstack up to 1.8.0. It has been declared as problematic. This vulnerability affects unknown code of the component AVRCP Browsing Target Handler. The manipulation of the argument attr_id results in out-of-bounds read.
This vulnerability is reported as CVE-2026-28528. The attacker must have access to the local network to execute the attack. No exploit exists.
It is recommended to upgrade the affected component.