Skip to main content
Disclosures

Bosch Sensortec · BHI360 SensorAPI

BHI360 Debug FIFO Stack Buffer Overflow

7.6high
SecMateSECMATE-2026-0032
VendorBosch Sensortec
ProductBHI360 SensorAPI
VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Advisories
Timeline
Reported
Nov 11, 2025
Published
Aug 31, 2026
Summary

Affected BHI360 SensorAPI revisions up to and including commit d6b200416a trust a sensor-controlled debug-frame length in bhi360_parse_debug_message() and copy it into a fixed 17-byte stack buffer without bounds checking. A malicious sensor, counterfeit module, or I2C/SPI bus participant can corrupt stack memory on the host MCU or SoC, causing denial of service and potentially arbitrary code execution.

Read the technical analysis

What's hidden in yours?

Find out