
[ZDI-26-156|CVE-2026-3558] (Pwn2Own) Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability (CVSS 8.1; Credit: Ho Xuan Ninh (@Xuanninh1412) and Hoang Hai Long (@seadragnol) from Qrious Secure (@qriousec)) https://www.zerodayinitiative.com/advisories/ZDI-26-156/
Post summary
The advisory announces CVE-2026-3558, an authentication bypass vulnerability in Philips Hue Bridge HomeKit Accessory Protocol with a CVSS score of 8.1, and provides a link to the Zero Day Initiative for further details.


