Control-Flow Hijack Vulnerability in Bluetooth Process of Microsoft Products
CVE-2026-49933
7.8HIGH
What is CVE-2026-49933?
A vulnerability exists in the Bluetooth process of various Microsoft products, where an uninitialized pointer dereference in handle_le_monitor_device_event can lead to a control-flow hijack. This flaw allows local escalation of privileges without requiring additional execution permissions, and user interaction is not necessary for exploitation.
Affected Version(s)
Android 17
Android 16-qpr2
Android 16