<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Bluetooth on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/bluetooth/</link><description>Recent content in Bluetooth on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Mon, 16 Jun 2025 02:13:48 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/bluetooth/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-11641: Chromium Bluetooth Use-After-Free in Edge</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-11641-chromium-bluetooth-use-after-free-microsoft-edge/</link><pubDate>Tue, 16 Jun 2026 02:13:48 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-11641-chromium-bluetooth-use-after-free-microsoft-edge/</guid><description>CVE-2026-11641 is a use-after-free flaw in Chromium&amp;#39;s Bluetooth component affecting Microsoft Edge. Learn the security impact and remediation steps.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11641">Microsoft Security Response Center</a></p>
<hr>
<p>A use-after-free vulnerability in the Bluetooth component of the Chromium engine (CVE-2026-11641) has been patched by Google and is being ingested into Microsoft Edge. Use-after-free flaws occur when a programme continues to use memory after freeing it, potentially allowing an attacker to execute arbitrary code. Although assigned under the Azure/Microsoft advisory, the root cause lies in Chromium and affects any Chromium-based browser, including Edge.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure Microsoft Edge deployments across your organisation are updated to the latest version as soon as the patched build is available; where Edge is used on Azure Virtual Desktop or enterprise endpoints, prioritise patch validation and consider enforcing browser version controls via Intune or Group Policy to limit exposure.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11641">Chromium: CVE-2026-11641 Use after free in Bluetooth</a></p>
]]></content:encoded></item><item><title>CVE-2026-11635: Chromium Bluetooth Use-After-Free in Edge</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-11635-chromium-bluetooth-use-after-free-microsoft-edge/</link><pubDate>Tue, 16 Jun 2026 02:13:40 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-11635-chromium-bluetooth-use-after-free-microsoft-edge/</guid><description>CVE-2026-11635 is a use-after-free flaw in Chromium&amp;#39;s Bluetooth component affecting Microsoft Edge. Learn the security impact and remediation steps.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11635">Microsoft Security Response Center</a></p>
<hr>
<p>A use-after-free vulnerability in the Chromium Bluetooth component has been assigned CVE-2026-11635 by the Chrome team. Microsoft Edge, being Chromium-based, is affected and has ingested the upstream fix from Google. Use-after-free flaws can allow attackers to execute arbitrary code by manipulating freed memory, making this a serious concern for end-user and enterprise browser security.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure Microsoft Edge is updated to the latest stable release that includes the patched Chromium build, and verify that your organisation&rsquo;s browser update policies enforce automatic updates. If Edge is deployed on Azure Virtual Desktop or corporate endpoints, prioritise rollout through Intune or your endpoint management tooling immediately.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11635">Chromium: CVE-2026-11635 Use after free in Bluetooth</a></p>
]]></content:encoded></item><item><title>CVE-2026-11633: Chromium Bluetooth Use-After-Free in Edge</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-11633-chromium-bluetooth-use-after-free-microsoft-edge/</link><pubDate>Tue, 16 Jun 2026 02:13:37 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-11633-chromium-bluetooth-use-after-free-microsoft-edge/</guid><description>CVE-2026-11633 is a use-after-free flaw in Chromium&amp;#39;s Bluetooth component affecting Microsoft Edge. Update Edge immediately to mitigate potential code exec</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11633">Microsoft Security Response Center</a></p>
<hr>
<p>A use-after-free vulnerability in the Bluetooth component of the Chromium browser engine has been assigned CVE-2026-11633. Microsoft Edge, which is built on Chromium, is affected and has ingested Google&rsquo;s upstream fix. Use-after-free flaws can allow attackers to execute arbitrary code by manipulating freed memory, potentially compromising the user&rsquo;s machine.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure Microsoft Edge is updated to the latest stable release across your enterprise estate, prioritising devices with Bluetooth enabled. Consider enforcing browser version compliance via Intune or your endpoint management tooling, and review whether Edge auto-update policies are active for managed endpoints.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11633">Chromium: CVE-2026-11633 Use after free in Bluetooth</a></p>
]]></content:encoded></item></channel></rss>