{"id":148495,"date":"2025-11-15T23:11:59","date_gmt":"2025-11-15T21:11:59","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/udalyonno-ekspluatiruemaya-uzvimost-v-bluetooth-steke-platformy-android"},"modified":"2025-11-15T23:11:59","modified_gmt":"2025-11-15T21:11:59","slug":"udalyonno-ekspluatiruemaya-uzvimost-v-bluetooth-steke-platformy-android","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonno-ekspluatiruemaya-uzvimost-v-bluetooth-steke-platformy-android","title":{"rendered":"Vuln\u00e9rabilit\u00e9 exploitable \u00e0 distance dans la pile Bluetooth de la plateforme Android","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Le bulletin de s\u00e9curit\u00e9 de novembre d'Android a publi\u00e9 des informations sur la vuln\u00e9rabilit\u00e9 CVE-2025-48593 dans le sous-syst\u00e8me Bluetooth, qui affecte les versions d'Android de 13 \u00e0 16. La vuln\u00e9rabilit\u00e9 est class\u00e9e comme critique (9,8 sur 10) car elle peut entra\u00eener une ex\u00e9cution de code \u00e0 distance lors du traitement de paquets Bluetooth sp\u00e9cialement con\u00e7us.    <\/p>\n<p>Google n'a pas encore divulgu\u00e9 de description d\u00e9taill\u00e9e de la vuln\u00e9rabilit\u00e9, mais des chercheurs ind\u00e9pendants affirment que le probl\u00e8me n'affecte pas les smartphones ordinaires et ne concerne que les appareils Bluetooth pouvant servir de haut-parleurs, tels que les enceintes intelligentes, les montres intelligentes et les syst\u00e8mes d'infodivertissement automobiles. L'exploitation n\u00e9cessite que l'utilisateur associe son appareil avec celui de l'attaquant, c'est-\u00e0-dire que pour \u00e9viter le probl\u00e8me, il suffit de ne pas accepter de demandes de couplage suspectes (le bulletin de Google mentionne que pour l'exploitation, aucune action de l'utilisateur n'est requise).    <\/p>\n<p>La correction consiste \u00e0 ajouter un appel pour v\u00e9rifier l'existence de la base de donn\u00e9es Discovery lors de l'utilisation du profil Bluetooth Handsfree et \u00e0 arr\u00eater la recherche de pairs en utilisant le protocole SDP (Service Discovery Protocol), ainsi qu'\u00e0 r\u00e9initialiser et \u00e0 nettoyer la structure p_disc_db (la \u00ab base de donn\u00e9es de d\u00e9couverte \u00bb). Certaines manipulations sont n\u00e9cessaires pour traiter les erreurs et reprendre les connexions lors de la d\u00e9tection du service Bluetooth et de la n\u00e9gociation de l'interaction. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/fr\/server\/dts-los-angeles\/\"   title=\"de serveurs\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3990\">de serveurs<\/a> avec le client conduisent \u00e0 acc\u00e9der \u00e0 une zone de m\u00e9moire d\u00e9j\u00e0 lib\u00e9r\u00e9e (use-after-free).     <\/p>\n<p>Le correctif a d\u00e9j\u00e0 \u00e9t\u00e9 int\u00e9gr\u00e9 dans la base de code de LineageOS. Un prototype pr\u00e9coce de l'exploit est disponible, provoquant un crash au d\u00e9marrage d'Android dans un \u00e9mulateur sp\u00e9cial. Des tentatives de vente d'un exploit op\u00e9rationnel ont \u00e9galement \u00e9t\u00e9 remarqu\u00e9es sur internet, mais il semble que ce soit des tentatives de diffusion de logiciels malveillants ou de vente de faux produits par des escrocs.                    <\/p>\n<p>En plus de cette vuln\u00e9rabilit\u00e9, la mise \u00e0 jour de novembre d'Android contient un correctif pour la vuln\u00e9rabilit\u00e9 CVE-2025-48581, entra\u00eenant une \u00e9l\u00e9vation des privil\u00e8ges. Le probl\u00e8me concerne uniquement Android 16 et est class\u00e9 comme critique. La cause de la vuln\u00e9rabilit\u00e9 est une erreur logique dans la fonction VerifyNoOverlapInSessions du fichier apexd.cpp, permettant de bloquer l'installation de mises \u00e0 jour corrigeant des probl\u00e8mes de s\u00e9curit\u00e9. Il est \u00e0 noter que la vuln\u00e9rabilit\u00e9 peut \u00eatre exploit\u00e9e pour une \u00e9l\u00e9vation des privil\u00e8ges au niveau local. Aucune action de la part de l'utilisateur n'est requise pour r\u00e9aliser l'attaque.<br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64255\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043d\u043e\u044f\u0431\u0440\u044c\u0441\u043a\u043e\u043c \u0431\u044e\u043b\u043b\u0435\u0442\u0435\u043d\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Android \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CVE-2025-48593 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 Bluetooth, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0432\u0435\u0440\u0441\u0438\u0438 Android \u0441 13 \u043f\u043e 16. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0439 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 (9.8 \u0438\u0437 10) \u0442\u0430\u043a \u043a\u0430\u043a \u043e\u043d\u0430 \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u043c\u0443 \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 Bluetooth-\u043f\u0430\u043a\u0435\u0442\u043e\u0432. \u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Google \u043f\u043e\u043a\u0430 \u043d\u0435 \u0440\u0430\u0441\u043a\u0440\u044b\u0432\u0430\u0435\u0442 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u043e\u043f\u0438\u0441\u0430\u043d\u0438\u044f \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u043d\u043e \u043d\u0435\u0437\u0430\u0432\u0438\u0441\u0438\u043c\u044b\u0435 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0443\u0442\u0432\u0435\u0440\u0436\u0434\u0430\u044e\u0442, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-148495","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043d\u043e\u044f\u0431\u0440\u044c\u0441\u043a\u043e\u043c \u0431\u044e\u043b\u043b\u0435\u0442\u0435\u043d\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Android \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CVE-2025-48593 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 Bluetooth, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0432\u0435\u0440\u0441\u0438\u0438 Android \u0441 13 \u043f\u043e 16.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonno-ekspluatiruemaya-uzvimost-v-bluetooth-steke-platformy-android\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043d\u043e\u044f\u0431\u0440\u044c\u0441\u043a\u043e\u043c \u0431\u044e\u043b\u043b\u0435\u0442\u0435\u043d\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Android \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CVE-2025-48593 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 Bluetooth, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0432\u0435\u0440\u0441\u0438\u0438 Android \u0441 13 \u043f\u043e 16.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonno-ekspluatiruemaya-uzvimost-v-bluetooth-steke-platformy-android\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-11-15T21:11:59+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-11-15T21:11:59+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9 exploit\u00e9e \u00e0 distance dans la pile Bluetooth de la plateforme Android | ProHoster","description":"Dans le bulletin de s\u00e9curit\u00e9 de novembre pour Android, des informations ont \u00e9t\u00e9 publi\u00e9es sur la vuln\u00e9rabilit\u00e9 CVE-2025-48593 dans le sous-syst\u00e8me Bluetooth, qui affecte les versions d'Android de 13 \u00e0 16.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonno-ekspluatiruemaya-uzvimost-v-bluetooth-steke-platformy-android","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u0434\u0430\u043b\u0451\u043d\u043d\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f \u0443\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Bluetooth-\u0441\u0442\u0435\u043a\u0435 \u043f\u043b\u0430\u0442\u0444\u043e\u0440\u043c\u044b Android | ProHoster","og:description":"\u0412 \u043d\u043e\u044f\u0431\u0440\u044c\u0441\u043a\u043e\u043c \u0431\u044e\u043b\u043b\u0435\u0442\u0435\u043d\u0435 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 Android \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d\u0430 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 CVE-2025-48593 \u0432 \u043f\u043e\u0434\u0441\u0438\u0441\u0442\u0435\u043c\u0435 Bluetooth, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0432\u0435\u0440\u0441\u0438\u0438 Android \u0441 13 \u043f\u043e 16.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/udalyonno-ekspluatiruemaya-uzvimost-v-bluetooth-steke-platformy-android","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-11-15T21:11:59+00:00","article:modified_time":"2025-11-15T21:11:59+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"148495","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-22 15:55:22","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 15:59:20","updated":"2026-02-22 15:55:22","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/148495","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=148495"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/148495\/revisions"}],"predecessor-version":[{"id":162519,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/148495\/revisions\/162519"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=148495"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=148495"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=148495"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}