CVE-2026-2411Active Exploitation(zephyrproject / zephyr)

MEDIUMCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch zephyrproject zephyr systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to BT_GATT_PERM_READ, and a Characteristic Value attribute that carries the application-specified security permissions (e.g. BT_GATT_PERM_READ_ENCRYPT / READ_AUTHEN / READ_LESC). The public notify and indicate APIs explicitly accept either attribute, and passing the declaration is the documented, common idiom. Before sending each notification or indication, the host re-checks link security with bt_gatt_check_perm() against params->attr in gatt_notify(), gatt_indicate(), and gatt_notify_multiple_verify_params() (subsys/bluetooth/host/gatt.c). When the application passed the Characteristic Declaration attribute, the host correctly redirected the value handle but left params->attr pointing at the declaration, so the security check evaluated the declaration's permissions (no security required) instead of the value's. As a result the encryption/authentication/LESC requirement configured on the characteristic value was skipped. The Notify-Multiple path additionally used a mask that omitted the LE Secure Connections requirement. A remote peer triggers the disclosure by connecting (optionally without pairing or encryption) and writing the Client Characteristic Configuration descriptor to enable notifications or indications, causing the server to emit the protected value over a link that has not reached the required security level. The impact is information disclosure / access-control bypass for characteristic values the application intended to expose only over a secured link; exposure depends on the application declaring encrypt/authen-required notify/indicate characteristics and on the CCC being writable at a lower security tier. There is no memory-safety or availability impact. The fix adds bt_gatt_attr_resolve_value(), which maps a declaration attribute to the following value attribute before the permission check, and switches the Notify-Multiple path to the full BT_GATT_PERM_READ_ENCRYPT_MASK so the LESC requirement is also enforced.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zephyr

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
zephyr

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-20: 1Active Exploitation · 2026-02-20: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-20: 102-20
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • hoonpto 훈토 | Premium+@Hoon_Pto
    Active Exploitation

    Chrome 윈/맥 버전 CSS 제로데이 취약점 업데이트 배포 1. 이번 이슈의 이름은 CVE-2026-2411 2. 그딴건 모르겠고 왜 문제냐? 3. 크롬의 CSS 처리 과정에서 발생하는 Use-After-Free 취약점임 4. 핵심은 해커가 가짜 웹사이트를 만들고, 유저가 그 페이지를 열기만 해도 임의 코드 실행, 비정상 동작 등이 가능함 5. 이론상 위험이 아닌 실제 누군가가 사용 중이라는 방법이라고 함 6. 해당 업데이트는 미루지말고 바로 진행할 것을 권고하고 있음 그래서 업데이트는 어떻게 해야하는데? 👇

    Post summary

    CVE‑2026‑2411 is a Use‑After‑Free flaw in Chrome’s CSS handling that is actively exploited via malicious sites, and users are urged to apply the update immediately.

    10010123
    908 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSzephyrprojectzephyr---

Explore more