PT-2023-7533 · Google · Android
CVE-2023-40088
·
Published
2023-12-01
·
Updated
2024-08-01
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions prior to the December 2023 security update
Description
The issue is related to a use after free vulnerability in the
callback thread event function of com android bluetooth btservice AdapterService.cpp. This could lead to remote code execution with no additional execution privileges needed. User interaction is not required for exploitation. The vulnerability was found in Android's System component.Recommendations
To resolve the issue, update your Android device to the December 2023 security update or later. Ensure that your device is set to receive automatic updates to protect against potential threats. As a temporary workaround, consider restricting Bluetooth functionality until the update is applied.
Fix
Use After Free
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android