CVE-2026-56988: Use After Free
Published Sep 15, 2026
·Updated
In multiple functions of bluetoothcco.cc, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 15, 2026
CVE Published
via MITRE·06:34 PM
Data Sourced
via MITRE·06:34 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Exploitation requires local access and System execution privileges. No user interaction is required.
2
What is the potential impact if exploitation succeeds?
The race-condition use-after-free could allow local escalation of privilege, with impacts to confidentiality, integrity, and availability.