top of page
perceptive_background_267k.jpg

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-cont…

Published:

27 July 2026 at 22:00:00

Alert date:

28 July 2026 at 20:07:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Zero-Day Vulnerabilities

A buffer overflow vulnerability has been identified in schreibfaul1's ESP32-audioI2S library version 3.4.5. The flaw exists in the MP3Decoder::UnpackSFMPEG1 function and is caused by missing input validation on attacker-controlled MP3 metadata. An attacker could exploit this vulnerability by crafting malicious MP3 metadata to trigger a buffer overflow. This affects embedded/IoT systems using the ESP32-audioI2S library for audio decoding. The vulnerability is tracked as CVE-2026-51252 and has been assigned a high criticality rating. Proof-of-concept advisory details are available on GitHub. Users of the affected library version should apply patches or mitigations as soon as they become available.

Technical details

Mitigation steps:

Affected products:

schreibfaul1 ESP32-audioI2S 3.4.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page