Remote exploit vulnerability in the Bluetooth stack of the Android platform

The November Android security bulletin has published information about the CVE-2025-48593 vulnerability in the Bluetooth subsystem, which affects Android versions 13 through 16. The vulnerability has been assigned a critical severity level (9.8 out of 10) as it can lead to remote code execution when processing specially crafted Bluetooth packets.

Google has not yet disclosed detailed information about the vulnerability, but independent researchers claim that the issue does not affect regular smartphones and only concerns Bluetooth devices capable of acting as speakers, such as smart speakers, smartwatches, and in-car infotainment systems. To exploit the vulnerability, the user must pair their device with the attacker's device; thus, to mitigate the issue, it is sufficient not to accept dubious pairing requests (Google's bulletin mentions that user action is not required for exploitation).

The fix involves adding a call to check for the existence of a Discovery Database when working with the Handsfree Bluetooth profile and stopping peer discovery using the Service Discovery Protocol (SDP), as well as resetting and cleaning the p_disc_db structure ("discovery database"). Specific manipulations related to error returns and re-establishing connections during Bluetooth service discovery and interaction negotiation with the client lead to access to already freed memory (use-after-free). server Some client interactions lead to access to already freed memory (use-after-free).

The fix has already been incorporated into the LineageOS codebase. An early prototype of an exploit that causes a crash when launching Android in a special emulator is available. There have also been attempts to sell a working exploit online, but these appear to be attempts at spreading malware or selling a fake product by scammers.

In addition to this vulnerability, the November Android update includes a fix for the CVE-2025-48581 privilege escalation vulnerability. This issue only affects Android 16 and is marked as critical. The vulnerability is caused by a logical error in the VerifyNoOverlapInSessions function in the apexd.cpp file, which allows blocking the installation of updates that fix security issues. It is noted that the vulnerability can be used for local privilege escalation. No user action is required for the attack.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster