CVE-2023-50230
CSIRTS triage
- What
- Heap-based buffer overflow in the Phone Book Access Profile allowing remote code execution.
- Who is affected
- Bluetooth devices running vulnerable BlueZ versions with PBAP enabled.
- Urgency
- High priority; remote code execution is possible, though currently not known to be exploited in the wild.
- Action
- Update BlueZ to a patched version addressing the buffer overflow in PBAP.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2023-50230
Get an email if CVE-2023-50230 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk1.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 72% of all EPSS-scored CVEs.
Advisory coverage (1)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2023-50230)