PT-2023-7533 · Google · Android

CVE-2023-40088

·

Published

2023-12-01

·

Updated

2024-08-01

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions prior to the December 2023 security update
Description The issue is related to a use after free vulnerability in the callback thread event function of com android bluetooth btservice AdapterService.cpp. This could lead to remote code execution with no additional execution privileges needed. User interaction is not required for exploitation. The vulnerability was found in Android's System component.
Recommendations To resolve the issue, update your Android device to the December 2023 security update or later. Ensure that your device is set to receive automatic updates to protect against potential threats. As a temporary workaround, consider restricting Bluetooth functionality until the update is applied.

Fix

Use After Free

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-291500341
BDU:2023-08587
CVE-2023-40088

Affected Products

Android