Files

TRACK-B-Broadcom-BCM4387-BroadScope

Strength: Provisional Track: B (vendor vulnerability disclosure) Status: Vendor acknowledged receipt; vendor characterized internally as "domain awareness, not technically discussing or anything at all" per filer's framing. No CVE assigned, no advisory published, no remediation timeline communicated as of this folder's creation.

Standing disclaimer: Filing and vendor acknowledgement does not constitute adjudication of the underlying technical claims.


What this case is

Coordinated-disclosure submission from filer (fr0mTheCloud@proton.me) to Broadcom PSIRT (psirt@broadcom.com) on 2026-03-09 20:17:38 UTC, reporting a vulnerability in the Broadcom BCM4387 / BCM4387C2 Wi-Fi/Bluetooth combo SoC. The filer assigns the working name "BroadScope" to the vulnerability and has published the forensic analysis as a public coordinated-disclosure research repository at github.com/JGoyd/BroadScope.

Broadcom replied 2026-03-10 18:13:49 -0700 (Daniel Edelson, with Ken Williams and the PSIRT alias on Cc). The reply body is PGP-encrypted to the filer's key (Proton-side encryption); only headers, MIME structure, and Broadcom's own DKIM/Authentication-Results envelope are verifiable from the build environment.

This is a strict Track B (technical vulnerability disclosure) case. No Track-A regulatory, financial, or investigative content is co-mingled in this folder.

Filer's role (precise language only)

  • Independent vulnerability researcher, sole filer of record on the Broadcom PSIRT thread.
  • Author of the public research repository github.com/JGoyd/BroadScope (commit head ba55b3f3c86b60ed63890a8c0f0f650c926f3baa, repo created 2026-04-03, last push 2026-04-07).
  • The repo contains README.md, VULNERABILITY_REPORT.md, THREAT_MODEL.md, and an evidence/ directory. Technical claims are byte-offset-anchored against two filer-provided artifacts: a 2,068,480-byte BCM4387C2 Wi-Fi SoC RAM dump (SoC_RAM.bin) and a 4,997,407-byte Bluetooth HCI packet log (bluetoothd-hci-2025-06-28_13-25-26.pklg). The repository explicitly disclaims weaponization: no exploit payloads or working PoC are present.

Vendor framing (filer-asserted, not adjudicated)

Per filer: Broadcom's reply (PGP-encrypted plaintext not readable from the build environment) was characterized as the vendor claiming domain awareness without technical engagement — i.e., acknowledging the report exists but neither confirming nor disputing the underlying technical findings. This framing is preserved verbatim for downstream readers; it is the filer's characterization of the encrypted reply, not an independent assessment.

External anchors (third-party-controlled)

Anchor URL / Identifier What it independently proves
BroadScope research repo (public) https://github.com/JGoyd/BroadScope Public coordinated-disclosure write-up by GitHub user JGoyd. Head commit ba55b3f3c86b…. Tree SHA bffbc5e4c458fdcd057db0f2c694c38f5bfabfb5. Created 2026-04-03T18:57:56Z, last push 2026-04-07T15:50:18Z. 2 stargazers at folder-creation time.
VULNERABILITY_REPORT.md (in repo) https://github.com/JGoyd/BroadScope/blob/main/VULNERABILITY_REPORT.md Detailed technical report with byte-offset-anchored evidence; commit 4c6720f8b5f5 (typo-fix commit 2090eb12b71f).
THREAT_MODEL.md (in repo) https://github.com/JGoyd/BroadScope/blob/main/THREAT_MODEL.md Threat-model analysis covering propagation-relevant capabilities.
Broadcom broadcom.com DKIM signature header b="BmLn+Zw1H0O5wsTUnPMHOWDE9Cz2…" The inbound reply is signed by Broadcom's google selector under broadcom.com (1024-bit RSA); Google's 1e100.net DKIM also countersigns. DMARC p=reject passes. SPF passes from broadcom.com. Cryptographically binds Broadcom as the originating organization for the envelope and headers of the 2026-03-10 reply.
Broadcom DLP relay path Received: from smtp-us-east1-p01-i01-si01.dlp.protect.broadcom.com (address-144-49-247-117.dlp.protect.broadcom.com. [144.49.247.117]) Confirms the message originated from inside Broadcom's enterprise DLP perimeter and was relayed to Google Workspace.
Daniel Edelson, Ken Williams (Broadcom PSIRT) daniel.edelson@broadcom.com, ken.williams@broadcom.com, psirt@broadcom.com Three named Broadcom corporate addresses on the reply, all under DKIM-signed broadcom.com.

Evidence files (staged in this folder)

File SHA-256 Role
evidence/Broadcom-PSIRT-Edelson-reply-2026-03-10.eml 7611c851392d2a6a7dc7fe46b8b8828beb2131de22607f1986f3129a758a25cf Full multipart/mixed inbound reply from Broadcom PSIRT (Edelson). PGP body, S/MIME attachment (smime.p7s).
evidence/Broadcom-PSIRT-Edelson-reply-headers-2026-03-10.txt bf70c42521795b2ceec6a94ddc0b1b62d1adba23486ea268f5fff7b8d3e44d58 Headers-only extract of the same inbound reply (filer-prepared, line-numbered).
evidence/Broadcom-PSIRT-outbound-headers-2026-03-09.txt 8b51b09039326255b35a44138ff14ba4468339fa5352a031cfad21ebdd12e08c Headers-only extract of the outbound PSIRT submission. Body PGP-encrypted from Proton compose side. Two attachments declared in headers: BCM4387 COEX Report.md and Broadcom COEX Submission 3.9.26.zip.

Message-Id of the canonical outbound: <IMSuEh9Qz-I_Y-5Exnqa0HSvbpUVePVXsEbJinMyqUbWZR7b804C8iq_MMBC1g0CUcn6t4_JV6soyHvEr5YTjbbEHluAsszfpFtcJIvtj8U=@proton.me> — this Message-Id appears as the first entry in the inbound References: chain, cryptographically threading the two messages.

Verification steps (anyone can run)

  1. Visit https://github.com/JGoyd/BroadScope and confirm: public repo, owner JGoyd, contains README.md / VULNERABILITY_REPORT.md / THREAT_MODEL.md / evidence/. Head commit at folder-creation time: ba55b3f3c86b60ed63890a8c0f0f650c926f3baa.
  2. Verify the inbound reply DKIM signature against broadcom.com selector google (1024-bit RSA): the bh= and b= values bind subject, sender, recipients, and date headers.
  3. Verify the Authentication-Results header in Broadcom-PSIRT-Edelson-reply-2026-03-10.eml: dkim=pass header.d=broadcom.com, dmarc=pass (p=reject), spf=pass smtp.mailfrom=broadcom.com.
  4. Confirm the References: chain in the inbound reply contains the filer's outbound Proton Message-Id (line 94 of the headers-only extract), establishing thread continuity.
  5. Confirm the Received: chain traces back to smtp-us-east1-p01-i01-si01.dlp.protect.broadcom.com [144.49.247.117], an authentic Broadcom enterprise DLP relay.

What this evidence does establish

  • A coordinated-disclosure submission was sent to Broadcom PSIRT on 2026-03-09 with two attached technical artifacts.
  • Broadcom (a named PSIRT engineer, with Ken Williams and the PSIRT alias) responded on 2026-03-10 from an authenticated Broadcom mail path.
  • A public, third-party-hosted (GitHub) research repository exists under the filer's verified GitHub login JGoyd documenting the BroadScope vulnerability with byte-offset-anchored forensic evidence.

What this evidence does not establish

  • The technical accuracy or severity of the underlying vulnerability claims (those are stated by the filer and verifiable only by independent firmware analysis).
  • Vendor agreement, disagreement, or any specific technical position from Broadcom — the reply body is PGP-encrypted and not readable from this build environment; the filer's characterization of "domain awareness, not technically discussing" is preserved as the filer's verbatim framing, not adjudicated.
  • Assignment of a CVE, publication of an advisory, or any remediation timeline.

Cross-references inside the system

  • TRACK-B-CVE-2025-24085-24201-43300 and TRACK-B-CVE-2025-31200-31201 — iOS CVE clusters where the filer is named as a CISA ADP rescoring contributor via cisagov/vulnrichment issues #194, #200, and #201. The BCM4387C2 SoC is present in iPhone 12-15 series per the BroadScope repo. Track-B-to-Track-B cross-reference for human navigation only.
  • TRACK-A-CISA-INC0625285-iOS-Bypass (batch 9, separate folder) — distinct CISA ServiceNow incident on a separate iOS security-bypass topic. Cross-reference here is informational; that case is on Track A (multi-recipient DHS distribution) and is not technically combined with BroadScope.

Disclosure status

  • Filer-side: Public research repository on GitHub since 2026-04-03; no exploit payloads or working PoC published.
  • Vendor-side (as of folder creation): Acknowledged receipt 2026-03-10; no public Broadcom advisory observed; no CVE assigned. Filer's characterization preserved verbatim above.

Open follow-ups

  • Watch for any Broadcom-published advisory or KB referencing BCM4387 / coexistence SRAM.
  • Watch for CVE assignment from MITRE referencing the same SoC/component.
  • Watch for any further PSIRT inbound on this thread (Message-Id chain anchored on the 2026-03-09 outbound).
  • The PGP-encrypted reply body can be decrypted by the filer offline; once decrypted, a paraphrase or pull-quote (filer's choice) may be added to this README — never the raw decrypted plaintext.

Safety notes

  • No exploit payloads, working PoC, or weaponized technical detail is staged in this folder. The forensic write-up in the linked repo is byte-offset-anchored to filer-supplied artifacts; reviewers wanting the underlying artifacts must obtain them directly from the filer subject to whatever conditions the filer sets.
  • The two header-extract .txt files contain only RFC-5322 envelope headers (sender, recipients, subject, date, Message-Id, References, DKIM/SPF/DMARC results, Received chain). No PGP plaintext is exposed.