PebbleOS
The Pebble smartwatch operating system.
Vulnerabilities affecting this build
To upgrade
nanopb 0.4.9.1 Upgrade to 0.4.9.2 or later2 vulnerabilities · an NVD scanner reports 0
- 54a7c338fe2b nanopb missed by NVD scannershigh
Unbounded recursion when cyclic messages are used
- d80739cff83c nanopb missed by NVD scannershigh
Callback field inside oneof can cause call into attacker-controlled function pointer
To look at
nimble 2ea18b9af381cb6741620fb710395b5d506d323d A vendor fork: check whether it carries the fixes10 vulnerabilities · an NVD scanner reports 10
- CVE-2026-45813 nimble high
Incorrect data validation in BASS add/modify source operation
- CVE-2026-45815 nimble high
Remote reachable assertion in ATT Read Multiple Variable Response handler
- CVE-2026-45811 nimble high
Buffer overflow in socket HCI transport
- CVE-2025-52435 nimble high
Invalid error handling in pause encryption procedure in NimBLE controller
- CVE-2025-62235 nimble high
Incorrect handling of SMP Security Request could lead to undesirable pairing
- CVE-2025-53477 nimble high
NULL Pointer Dereference in NimBLE host HCI layer
- CVE-2026-45816 nimble high
NULL pointer dereference vulnerability in SMP LTK request
- CVE-2026-45812 nimble medium
OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
- CVE-2026-46452 nimble medium
Mesh Proxy SAR reassembly unbounded append and unchecked failure
- CVE-2025-53470 nimble low
Out-of-Bounds Write Vulnerability in NimBLE HCI H4 driver
freertos-kernel 8583941bff119369cad8dc65489a7d05140f5f67 Version numbers can't settle this. Have a look.5 vulnerabilities · an NVD scanner reports 5
- CVE-2026-77235 freertos high
Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel
- CVE-2026-77236 freertos high
Missing size validation in SecureContext_AllocateContext in FreeRTOS-Kernel
- CVE-2026-77234 freertos high
Improper input validation in FreeRTOS-Kernel timer command handling
- CVE-2024-28115 freertos high
Potential Privilege Escalation in FreeRTOS Kernel ARMv7-M MPU ports and ARMv8-M ports with MPU support enabled
- CVE-2026-77237 freertos medium
Missing type validation in xQueueAddToSet in FreeRTOS-Kernel
No advisory source
- cmsis-5 5.0.0..
- iconography 99e2660ccd8c0c98e596612bb1c21700e28156b3
- memfault-firmware-sdk 1.24.0
- moddable 25f1a3bb1e47d1dff750d4571ae314239735bee9
- nrfx 3.11.0
- pebbleos-nonfree fd47756358e16b4f791bf8a4de08acdcbee84db5
- picolibc 2cb62b35aaf461e730860cb7ecc31c51b9848d78
- qr-code-generator 1.8.0..
- speex 1.2.1..
- tinymt 1.1.2..
How this was made, and what it is not
We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.
It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.