CVE-2025-22408
published 2025-08-26CVE-2025-22408: In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.37%
29.7th percentile
In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | packages_modules_bluetooth | >= 15-next:0 < 15-next:2025-03-01 | 15-next:2025-03-01 |
| platform | packages_modules_bluetooth | >= 15:0 < 15:2025-03-01 | 15:2025-03-01 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target function for UAF vulnerability is `rfc_check_send_cmd` in `rfc_utils.cc` — monitor for anomalous RFCOMM command processing or crashes originating from this function in Android Bluetooth stack ↗
- →Vulnerability is remotely exploitable with no privileges and no user interaction required — treat any unexpected Bluetooth RFCOMM traffic or connection attempts to unpatched Android 15 devices as potentially malicious ↗
- →Only Android 15 is listed as an affected AOSP version — scope detection and patching efforts to devices running AOSP 15 that have not applied the 2025-03-01 security patch level ↗
- →Internal Android bug tracker reference A-375397164 can be used to cross-reference patch commits in AOSP Gerrit for diff-based detection rule development ↗
- ·No public proof-of-concept or exploit code was referenced in the available sources; IOC extraction is not possible without observed attacker infrastructure or payload artifacts ↗
- ·Severity is CRITICAL and the attack vector is remote with zero interaction, meaning exploitation leaves minimal host-based indicators prior to code execution — network-layer Bluetooth anomaly detection is the primary pre-exploitation signal ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2025-22408: Android Security Bulletin 2025-03-01
CVE: CVE-2025-22408
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 15
References: A-375397164
vendor_android·2025-03-01·CVSS 9.8
CVE-2025-22408 [CRITICAL] CVE-2025-22408: Android Security Bulletin 2025-03-01
CVE: CVE-2025-22408
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 15
References: A-375397164
Android Security Bulletin 2025-03-01
CVE: CVE-2025-22408
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 15
References: A-375397164
GHSA
GHSA-xj8c-32pp-9795: In rfc_check_send_cmd of rfc_utils
ghsa_unreviewed·2025-08-27
CVE-2025-22408 [CRITICAL] CWE-416 GHSA-xj8c-32pp-9795: In rfc_check_send_cmd of rfc_utils
In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2025-22408: In rfc_check_send_cmd of rfc_utils
osv·2025-03-01
CVE-2025-22408 CVE-2025-22408: In rfc_check_send_cmd of rfc_utils
In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-26
Published