CVE-2023-21108: Use After Free
In sdpubuilduuidseq of sdpdiscovery.cc, there is a possible out of bounds write due to a use after free. This could lead to remote code execution over Bluetooth, if HFP support is enabled, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-239414876
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21108?
CVE-2023-21108 has a high severity due to its potential for remote code execution over Bluetooth.
How do I fix CVE-2023-21108?
To fix CVE-2023-21108, ensure that your Android device is updated to the latest security patch provided by Google.
Which versions of Android are affected by CVE-2023-21108?
CVE-2023-21108 affects Android versions 11.0, 12.0, 12.1, and 13.0.
Is user interaction required to exploit CVE-2023-21108?
No, user interaction is not needed for the exploitation of CVE-2023-21108.
What could happen if CVE-2023-21108 is exploited?
If exploited, CVE-2023-21108 could lead to remote code execution, potentially allowing an attacker to gain control of the affected device.