Automotive
Denial of Service
Bluetooth Classic LMP Handle Flaw Exploitation
The vulnerability affects the stability and reliability of the vehicle's infotainment system by allowing unauthenticated Bluetooth Classic traffic to interact with low-level protocol handling.
.png)
Overview
The infotainment unit uses a Bluetooth Classic (BR/EDR) chipset that contains a flaw in how it processes low-level LMP control messages during wireless communication. Due to improper validation of these packets, the Bluetooth controller inside the infotainment system can be pushed into an invalid or unexpected state when it receives malformed or out-of-sequence control messages from a nearby device.
Vulnerability details
The infotainment unit uses a Bluetooth Classic (BR/EDR) chipset that contains a flaw in how it processes low-level LMP control messages during wireless communication.
What an attacker can do
The vulnerability affects the stability and reliability of the vehicle's infotainment system by allowing unauthenticated Bluetooth Classic traffic to interact with low-level protocol handling. Since the issue occurs at the LMP controller layer, malformed control messages can be processed before any pairing or authentication takes place. As a result, the infotainment unit may enter an unstable state, leading to crashes, denial-of-service conditions, or sudden reboots triggered by external, non-trusted Bluetooth devices. This behavior exposes the system to unauthenticated disruption through its Bluetooth Classic interface.
Disclosure timeline
2025-09-23 Reported to Vendor
2025-11-20 CVE ID Reserved
2025-12-11 CVE published
References
Credits
Shubham S. Thorat – Payatu Security Consulting Pvt. Ltd.
















