CVE-2025-22412: Use After Free
In multiple functions of sdpserver.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22412?
CVE-2025-22412 is considered a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-22412?
To fix CVE-2025-22412, update the affected Google Android software to the latest security patch released by Google.
Who is affected by CVE-2025-22412?
CVE-2025-22412 affects users of Google Android due to vulnerabilities in the Bluetooth module.
What type of vulnerability is CVE-2025-22412?
CVE-2025-22412 is a use after free vulnerability caused by a logic error in the sdp_server.cc code.
Is user interaction required to exploit CVE-2025-22412?
No, user interaction is not required to exploit CVE-2025-22412, making it easier for an attacker to exploit.