Remote Code Execution Vulnerability in Bluetooth Module by Google
CVE-2025-22408

9.8CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-22408?

A vulnerability exists in the Bluetooth module of Google's Android operating system, specifically within the rfc_check_send_cmd function of rfc_utils.cc. This flaw creates a condition where an attacker can exploit a use after free scenario, potentially allowing for remote code execution without requiring any user interaction or elevated privileges. This vulnerability poses significant risks, particularly in environments where devices are interconnected and susceptible to external attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Android 15

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.