- Synacktiv describes CVE-2026-3555, a memory flaw in the Philips Hue Bridge reached over Zigbee, and says it was exploited during Pwn2Own Ireland.
- Synacktiv says the flaw is reached through a state that commissioning a Zigbee device sets off. Physical access was for analysis; the exploit is delivered over Zigbee.
- The Hue Bridge is a consumer device. Leaders can use the findings to ask vendors about radio-facing code, pairing controls and fix status.
A lightbulb hub with its own radio
Philips Hue bridges talk to smart bulbs over Zigbee, a short-range radio protocol. Synacktiv, a security firm, published research on how to get remote code execution on a Hue Bridge from the Zigbee network. The firm says the vulnerability was exploited during Pwn2Own, a contest held in Cork, Ireland.
The Hue Bridge is a consumer product. This story is not about offices. It is about what the research shows of how connected devices are built.
What Synacktiv did
This edition of Pwn2Own added smart home devices for the first time. Targets included Amazon's smart plug, the Home Assistant Green and the Hue Bridge. The contest rules allowed attackers on the local network or on a nearby radio link such as Wi-Fi, Bluetooth or Zigbee. Only the standard Hue Bridge was a target. The Pro model, released in 2025, was not.
Synacktiv reports that the other teams all went after hk_hap, the service that connects the bridge to Apple HomeKit. Typically they skipped the login step and then corrupted memory. Synacktiv took the radio route instead. It says it wanted to avoid bug collisions with other teams.
The lab setup was not remote. To study the device, Synacktiv first got a shell on it. That meant shorting a specific pin during boot, which let the team reset keys and turn on SSH. Several blog posts, it notes, describe this step. That physical step was groundwork for analysis. The exploit itself is delivered over the Zigbee network.
How the bridge is built
Nearly everything on the bridge sits in one large program called ipbridge. It runs on a MIPS processor under Linux. Several copies of it run at once to handle services such as Apple HomeKit and Matter.
Radio messages first reach a separate controller chip. It turns them into text and passes them to ipbridge. Synacktiv focused on manufacturer-specific messages. These are not standardized, so the firm says they are more prone to coding errors.
The flaw, and the catch
A Philips bulb sends model information to the bridge in fragments. The bridge checks the claimed total against a ceiling of 0x2800 bytes, about 10 kilobytes. It never checks the incoming fragment against the size of the buffer it actually allocated. Two crafted messages are enough. The first claims a small total. The second carries more data than the buffer holds. The data spills into the next block of memory. The flaw is tracked as CVE-2026-3555.
There is a catch. Synacktiv says the vulnerable code cannot be reached directly. A process called Download Blob must be in a particular state. Another process, Configure Devices, sets that off when the bridge commissions a newly discovered Zigbee device. For a Philips bulb, the bridge then asks for its model information.
Pairing starts when a user scans from the app or presses the button on the casing. The excerpt we reviewed does not explain how an attacker would trigger this step. That limits what can be said about real-world exposure.
From memory bug to reverse shell
The overflow alone did not give control. The bridge uses a modified version of the dlmalloc memory allocator, shipped in musl libc 1.1.24. An allocator is the code that hands out and reclaims memory. Synacktiv set a neighboring block's recorded size to a "negative" value. When the vulnerable buffer was freed, the allocator walked into fake blocks the team had planted. Each fake block caused a four-byte write to an address the team chose.
Those writes placed a minimal piece of code in memory. It called the system function with a command that starts a reverse shell, which makes the device connect back to the attacker. Synacktiv then redirected a function pointer the bridge uses to read Zigbee frames. That function is called often and on a regular cycle. Synacktiv says this made it a good trigger, because the code ran before the allocator's damaged state could crash the system.
What the research leaves open
The excerpt does not say whether Philips has released a fix. It does not cover the Pro model. Matter, mDNS and UPnP were not examined. The flaw sits in one Philips-specific message handler, not in the whole Zigbee stack.
What the research suggests
The lesson here is an argument, not a finding. A device's radio is a way in that a network firewall does not watch. Synacktiv's account points to two ingredients that made the radio path workable. Vendor-specific messages have no common standard, and the firm says that makes them more error-prone. A modified allocator could be turned against itself to give a write primitive.
We would add a third factor, as our own reading. Nearly all the bridge's functions sit in one large program, so a single flaw in a message handler lands inside code that does most of the work. Synacktiv does not make this claim.
Separately, some general Zigbee background. Synacktiv notes that the protocol's default link key is "ZigBeeAlliance09" and that it protects the handoff of the network key during pairing. Zigbee 3.0 devices use a unique install code instead. This is not part of Synacktiv's exploit chain for CVE-2026-3555.
If your organization runs any hub with a radio, whatever the brand, put four questions to the vendor. Which radio protocols does it accept? Who can start pairing, and is that controlled? Do firmware updates install themselves? Has a fix for any known radio flaw been confirmed? For the Hue Bridge, that last question applies to CVE-2026-3555.
If a device has a radio, that radio belongs in the security review.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Synacktiv.





