CVE-2025-22411: Use After Free
In processserviceattrrsp of sdpdiscovery.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22411?
CVE-2025-22411 is rated as high severity due to the potential for remote code execution.
How do I fix CVE-2025-22411?
To fix CVE-2025-22411, update your Google Android device to the latest security patch provided by Google.
What type of vulnerability is CVE-2025-22411?
CVE-2025-22411 is a use after free vulnerability found in the management of service attributes in Bluetooth.
Who is affected by CVE-2025-22411?
CVE-2025-22411 affects devices running specific versions of Google Android that incorporate the vulnerable Bluetooth software.
Can CVE-2025-22411 be exploited without user interaction?
Yes, CVE-2025-22411 can be exploited remotely without user interaction required.