Skip to content
ZDI-26-154

ZDI-26-154

Zerodayinitiative March 7, 2026

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the hk_hap_pair_storage_put function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the HomeKit service.

Fixed in Bridge v2 Software version 1975170000

Extracted Entities

Attack Types (1)