CVE-2023-21130
published 2023-06-15CVE-2023-21130: In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code…
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.53%
41.2th percentile
In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-273502002
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_bluetooth | >= 13-next:0 < 13-next:2023-06-01 | 13-next:2023-06-01 |
| platform | packages_modules_bluetooth | >= 13:0 < 13:2023-06-01 | 13:2023-06-01 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability resides in the `btm_ble_periodic_adv_sync_lost` function within `btm_ble_gap.cc` in the Android Bluetooth stack — monitor for crashes or anomalous behavior in this code path on Android 13 devices ↗
- →Target scope is Android 13 exclusively — prioritize detection and patching efforts on devices running AOSP version 13 ↗
- →No user interaction is required for exploitation — the attack is fully remote and zero-click, making passive Bluetooth traffic monitoring critical for detection ↗
- →No additional execution privileges are needed — a successful exploit grants code execution at the Bluetooth process privilege level without any prior foothold ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2023-21130: Android Security Bulletin 2023-06-01
CVE: CVE-2023-21130
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 13
References: A-273502002
vendor_android·2023-06-01·CVSS 9.8
CVE-2023-21130 [CRITICAL] CVE-2023-21130: Android Security Bulletin 2023-06-01
CVE: CVE-2023-21130
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 13
References: A-273502002
Android Security Bulletin 2023-06-01
CVE: CVE-2023-21130
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 13
References: A-273502002
GHSA
GHSA-7v3q-qm7v-h2c2: In btm_ble_periodic_adv_sync_lost of btm_ble_gap
ghsa_unreviewed·2023-06-15
CVE-2023-21130 [CRITICAL] CWE-125 GHSA-7v3q-qm7v-h2c2: In btm_ble_periodic_adv_sync_lost of btm_ble_gap
In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-273502002
OSV
CVE-2023-21130: In btm_ble_periodic_adv_sync_lost of btm_ble_gap
osv·2023-06-01
CVE-2023-21130 CVE-2023-21130: In btm_ble_periodic_adv_sync_lost of btm_ble_gap
In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-15
Published