CVE-2023-21250: Critical severity android vulnerability
Published Jul 5, 2023
·Updated
In gattendoperation of gattutils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
5 affected components
Google Android=11.0
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android
Remediation
Patch Available
Event History
Jul 5, 2023
CVE Published
via Android·12:00 AM
Jul 12, 2023
CVE Published
via MITRE·11:32 PM
Data Sourced
via MITRE·11:32 PM
DescriptionWeakness
Jul 13, 2023
Data Sourced
12:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-21250?
CVE-2023-21250 is classified as a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2023-21250?
To fix CVE-2023-21250, update your Android device to the latest security patch or version provided by Google.
3
Which Android versions are affected by CVE-2023-21250?
CVE-2023-21250 affects Android versions 11.0, 12.0, 12.1, and 13.0.
4
Is user interaction required to exploit CVE-2023-21250?
No, user interaction is not needed for the exploitation of CVE-2023-21250.
5
What type of vulnerability is CVE-2023-21250?
CVE-2023-21250 is an out of bounds write vulnerability in the Bluetooth stack of Android.