Remote Code Execution Vulnerability in Bluetooth Module by Google
CVE-2025-22408

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-22408?

A vulnerability exists in the Bluetooth module of Google's Android operating system, specifically within the rfc_check_send_cmd function of rfc_utils.cc. This flaw creates a condition where an attacker can exploit a use after free scenario, potentially allowing for remote code execution without requiring any user interaction or elevated privileges. This vulnerability poses significant risks, particularly in environments where devices are interconnected and susceptible to external attacks.

Affected Version(s)

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22408 : Remote Code Execution Vulnerability in Bluetooth Module by Google