CVE-2026-87961 | schreibfaul1 ESP32-audioI2S up to 4.0.0 ID3 Synchronized-Lyrics Processing read_ID3_Header out-of-bounds (EUVD-2026-75388)
A vulnerability was found in schreibfaul1 ESP32-audioI2S up to 4.0.0. It has been rated as critical. Affected by this vulnerability is the function read_ID3_Header of the component ID3 Synchronized-Lyrics Processing. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-87961. The attack is possible to be carried out remotely. No exploit exists.