Skip to main content
Disclosures

Bosch Sensortec · COINES SDK

COINES Streaming Destination Buffer Overflow

6.8medium
SecMateSECMATE-2026-0036
VendorBosch Sensortec
ProductCOINES SDK
VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Advisories
Timeline
Reported
Nov 11, 2025
Published
Aug 31, 2026
Summary

COINES SDK versions 2.0 through 2.11 can copy accumulated USB or BLE stream data into a caller-provided destination without validating its capacity. A malicious or compromised board can overflow heap or stack memory in the host application, causing denial of service or potentially arbitrary code execution.

Read the technical analysis

What's hidden in yours?

Find out