Use After Free Vulnerability in Android Bluetooth Stack
CVE-2025-22409

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-22409?

A vulnerability exists in the Android Bluetooth stack owing to a use after free condition in the rfc_send_buf_uih function within rfc_ts_frames.cc. This flaw allows for potential arbitrary code execution, enabling local escalation of privilege without requiring additional execution permissions or user interaction. Proper patches are essential to mitigate this risk, as exploitation can occur even without any actions from the user.

Affected Version(s)

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22409 : Use After Free Vulnerability in Android Bluetooth Stack