Code Execution Risk in Android Bluetooth System by Vendor Google
CVE-2026-58880
7HIGH
What is CVE-2026-58880?
A vulnerability within the Android Bluetooth system allows for potential code execution due to a race condition in the handling of application response validation. This flaw could enable an attacker to execute arbitrary code on the user's device without requiring any user interaction or elevated permissions. The affected component is located in the btif_rc.cc file, and it is crucial for users to ensure that their Android devices are up-to-date with the latest security patches to mitigate the risks associated with this vulnerability.
Affected Version(s)
Android 17
Android 16-qpr2
Android 16