Arbitrary Code Execution Vulnerability in Android Bluetooth Service
CVE-2025-22403

9.8CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-22403?

A vulnerability exists in the Android Bluetooth service that allows for potential remote code execution due to a use after free condition in the 'sdp_snd_service_search_req' function. This flaw does not require additional execution privileges or user interaction for exploitation, making it particularly concerning for users and organizations relying on secure Bluetooth communications.

Affected Version(s)

Android 15

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.