CVE-2025-32330: Medium severity Google Android vulnerability
In generateRandomPassword of LocalBluetoothLeBroadcast.java, there is a possible way to intercept the Auracast audio stream due to an insecure default value. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32330?
The severity of CVE-2025-32330 is categorized as moderate due to the potential for information disclosure.
How do I fix CVE-2025-32330?
To fix CVE-2025-32330, update to the latest version of Android that addresses the insecure default value used in the Auracast audio stream.
What type of information is exposed by CVE-2025-32330?
CVE-2025-32330 could lead to remote information disclosure by allowing interception of the Auracast audio stream.
What platforms are affected by CVE-2025-32330?
CVE-2025-32330 specifically affects Google Android devices utilizing the impacted LocalBluetoothLeBroadcast feature.
Is user interaction required to exploit CVE-2025-32330?
No, CVE-2025-32330 does not require user interaction to exploit the vulnerability.