Practical exploitability of BrainFlow analyser findings
Establish whether the triaged externally controlled format-string sites and potential memory-corruption sites identified in BrainFlow 5.18.0 are exploitable in practice, including whether they can support a working control-flow hijack or arbitrary code execution.
References
We did not develop a working control-flow hijack from these sites, and we therefore make no claim of arbitrary code execution. What we confirmed dynamically is narrower but concrete: the OpenBCI GUI invokes BrainFlow helper components without privilege separation, so code executing inside a helper inherits the launching process's privileges rather than a reduced set. Establishing whether the triaged sites are exploitable in practice is left to future work; all findings were reported to the maintainers (Section~\ref{sec:disclosure}).