Skip to main content
Disclosures

Bosch Sensortec · BHI360 SensorAPI

BHI360 Debug FIFO Stack Buffer Overflow

7.6high
SecMateSECMATE-2026-0032
VendorBosch Sensortec
ProductBHI360 SensorAPI
VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Advisories
Timeline
Reported
Nov 11, 2025
Published
Aug 31, 2026
Summary

Affected BHI360 SensorAPI revisions up to and including commit d6b200416a trust a sensor-controlled debug-frame length in bhi360_parse_debug_message() and copy it into a fixed 17-byte stack buffer without bounds checking. A malicious sensor, counterfeit module, or I2C/SPI bus participant can corrupt stack memory on the host MCU or SoC, causing denial of service and potentially arbitrary code execution.

What's hidden in yours?

Find out