cbcvebase.
CVE-2023-20951
published 2023-03-24

CVE-2023-20951: In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution…

PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.49%
38.8th percentile
In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-258652631

Affected

11 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformpackages_modules_bluetooth>= 13-next:0 < 13-next:2023-03-0113-next:2023-03-01
platformpackages_modules_bluetooth>= 13:0 < 13:2023-03-0113:2023-03-01
platformsystem_bt>= 11:0 < 11:2023-03-0111:2023-03-01
platformsystem_bt>= 12:0 < 12:2023-03-0112:2023-03-01
platformsystem_bt>= 12L:0 < 12L:2023-03-0112L:2023-03-01

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is in gatt_process_prep_write_rsp function within gatt_cl.cc — monitor for anomalous Bluetooth GATT Prepare Write Response handling on Android devices
  • No user interaction required and no additional privileges needed — exploit can be delivered entirely remotely over Bluetooth, making zero-click Bluetooth traffic anomalies a key detection signal
  • Affected Android versions are 11, 12, 12L, and 13 — prioritize detection and patching on unpatched devices running these OS versions
  • ·Patch is tracked under Android internal bug ID A-258652631 and was released in the March 2023 Android Security Bulletin — devices must be on or above the 2023-03-01 security patch level to be protected
  • ·Severity is rated CRITICAL with RCE impact and no interaction required, meaning unpatched devices with Bluetooth enabled are at maximum risk without any user action
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.