First published: Mon Dec 04 2023(Updated: )
In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
=11.0 | ||
=12.0 | ||
=12.1 | ||
=13.0 | ||
=14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2023-40088.
CVE-2023-40088 has a severity rating of critical.
The software affected by CVE-2023-40088 is Google Android.
No, user interaction is not needed for exploitation of CVE-2023-40088.
Yes, you can find references for CVE-2023-40088 at the following links: [1](https://source.android.com/security/bulletin/2023-12-01) and [2](https://source.android.com/docs/security/bulletin/2023-12-01).