Code Execution Risk in Android Bluetooth System by Vendor Google
CVE-2026-58880

7HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-58880?

A vulnerability within the Android Bluetooth system allows for potential code execution due to a race condition in the handling of application response validation. This flaw could enable an attacker to execute arbitrary code on the user's device without requiring any user interaction or elevated permissions. The affected component is located in the btif_rc.cc file, and it is crucial for users to ensure that their Android devices are up-to-date with the latest security patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

Android 17

Android 16-qpr2

Android 16

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.