Remote Code Execution Vulnerability in Android Bluetooth Module
CVE-2025-22412

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-22412?

A logic error in the code of the Android Bluetooth module (sdp_server.cc) allows for a possible use after free scenario, which can enable remote code execution. This vulnerability can be exploited without requiring user interaction, posing a significant risk to systems that utilize affected versions of Android. Proper patches and updates are crucial in mitigating this security threat.

Affected Version(s)

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-22412 : Remote Code Execution Vulnerability in Android Bluetooth Module