
[ZDI-26-159|CVE-2026-3561] (Pwn2Own) Philips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 8.0; Credit: Thalium team from Thales Group (@thalium_team)) https://www.zerodayinitiative.com/advisories/ZDI-26-159/
Post summary
The advisory announces a heap-based buffer overflow vulnerability (CVE-2026-3561) in Philips Hue Bridge that allows remote code execution, with an assessed CVSS score of 8.0.


