


Perceptive Security
SOC/SIEM Consultancy

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showID3Tag() of the embedded audio strea…
Published:
28 July 2026 at 00:00:00
Alert date:
28 July 2026 at 22:07:40
Source:
nvd.nist.gov
Mobile & IoT, Zero-Day Vulnerabilities, Critical Infrastructure
A heap-based buffer overflow vulnerability (CVE-2026-51273) has been identified in schreibfaul1 ESP32-audioI2S version 3.4.5, an embedded audio streaming library for ESP32 microcontrollers. The flaw resides in the ID3 tag parsing function showID3Tag(), which uses an unbounded appendf() call to write formatted strings into a heap buffer (ps_ptr) without performing any length validation. Attackers can exploit this vulnerability by crafting malicious audio files containing excessively long ID3 tag values. Successful exploitation may result in arbitrary code execution, sensitive memory data leakage, device crashes, or privilege escalation. The vulnerability poses a significant risk to IoT and embedded devices running the affected library version. No patch information is noted in the article, and the issue was submitted to NVD.
Technical details
Mitigation steps:
Affected products:
schreibfaul1 ESP32-audioI2S 3.4.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51273
https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51273
https://github.com/schreibfaul1/ESP32-audioI2S/blob/master/src/Audio.cpp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
