Arbitrary Code Execution Vulnerability in Android Bluetooth Modules
CVE-2025-0074

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-0074?

A vulnerability exists in Android Bluetooth modules where a use after free condition in the process_service_attr_rsp function of sdp_discovery.cc could allow attackers to execute arbitrary code remotely. This exploitation does not require user interaction and can potentially compromise device integrity.

Affected Version(s)

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-0074 : Arbitrary Code Execution Vulnerability in Android Bluetooth Modules