What is CVE-2026-10680?
This critical vulnerability resides in the Classic (BR/EDR) Bluetooth L2CAP signaling handlers where insufficient command size validation could lead to memory corruption. An attacker in physical proximity could exploit this by sending crafted packets to cause a denial-of-service or potentially execute arbitrary code. Users should disable Bluetooth when not in use and apply the vendor's security patch immediately upon availability.
Azərbaycanca: Bu kritik boşluq Bluetooth Classic (BR/EDR) protokolunda L2CAP siqnal idarəedicilərində aşkarlanıb. Zərərli qurğular xüsusi hazırlanmış paketlər göndərərək yanlış ölçü doğrulaması səbəbindən yaddaş pozuntusuna səbəb ola bilər. İstifadəçilər Bluetooth-u müvəqqəti söndürməli və istehsalçı tərəfindən təhlükəsizlik yeniləməsi təqdim edilən kimi tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
What immediate action should be taken to protect against CVE-2026-10680?
Users should disable Bluetooth temporarily and apply the vendor's security patch immediately upon availability.
In which protocol component was CVE-2026-10680 discovered?
This vulnerability was discovered in the Classic (BR/EDR) Bluetooth L2CAP signaling handlers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.