cbcvebase.

Platform Packages Modules Bluetooth vulnerabilities

119 known vulnerabilities affecting platform/packages_modules_bluetooth.

Total CVEs
119
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
UNKNOWN119

Vulnerabilities

Page 4 of 6
CVE-2023-20985P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20985 CVE-2023-20985: In BTA_GATTS_HandleValueIndication of bta_gatts_api In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20936P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20936 CVE-2023-20936: In bta_av_rc_disc_done of bta_av_act In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20967P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 13:0, < 13:2023-04-012023-04-01
CVE-2023-20967 CVE-2023-20967: In avdt_scb_hdl_pkt_no_frag of avdt_scb_act In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-45866P3UNKNOWN≥ 14-next:0, < 14-next:2023-12-05≥ 13:0, < 13:2023-12-05+1 more2023-12-01
CVE-2023-45866 CVE-2023-45866: In multiple locations, there is a possible way to inject keystrokes due to improper input validation In multiple locations, there is a possible way to inject keystrokes due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20547P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20547 CVE-2022-20547: In multiple functions of AdapterService In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20207P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-012022-06-01
CVE-2022-20207 CVE-2022-20207: In TBD of GattDebugUtils In TBD of GattDebugUtils.java, there is a possible permission bypass due to accidentally enabling debug_admin . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35666P3UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 13:0, < 13:2023-09-012023-09-01
CVE-2023-35666 CVE-2023-35666: In bta_av_rc_msg of bta_av_act In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20461P3UNKNOWN≥ 13:0, < 13:2023-01-012023-01-01
CVE-2022-20461 CVE-2022-20461: In pinReplyNative of com_android_bluetooth_btservice_AdapterService In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege of BLE with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40090P3UNKNOWN≥ 13:0, < 13:2023-12-01≥ 14:0, < 14:2023-12-012023-12-01
CVE-2023-40090 CVE-2023-40090: In BTM_BleVerifySignature of btm_ble In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26441P3UNKNOWN≥ 16-next:0, < 16-next:2025-06-01≥ 15:0, < 15:2025-06-01+2 more2025-06-01
CVE-2025-26441 CVE-2025-26441: In add_attr of sdp_discovery In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20126P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-012022-06-01
CVE-2022-20126 CVE-2022-20126: In setScanMode of AdapterService In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-0092P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 15:0, < 15:2025-03-01+2 more2025-03-01
CVE-2025-0092 CVE-2025-0092: In handleBondStateChanged of AdapterService In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-24023P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+2 more2025-09-01
CVE-2023-24023 CVE-2023-24023: In multiple locations, there is a possible way to impersonate and MitM a device across session by only compromising one session key due to an insecure In multiple locations, there is a possible way to impersonate and MitM a device across session by only compromising one session key due to an insecure protocol design on Bluetooth Legacy Secure Connection (LSC). This could lead to remote escalation of privilege with no additional execution privileges needed. User int
osv
CVE-2024-0045P4UNKNOWN≥ 14-next:0, < 14-next:2024-03-01≥ 13:0, < 13:2024-03-01+1 more2024-03-01
CVE-2024-0045 CVE-2024-0045: In smp_proc_sec_req of smp_act In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43766P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+2 more2026-03-01
CVE-2024-43766 CVE-2024-43766: In multiple functions of btm_ble_sec In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22407P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 15:0, < 15:2025-03-012025-03-01
CVE-2025-22407 CVE-2025-22407: In hidd_check_config_done of hidd_conn In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20447P4UNKNOWN≥ 13:0, < 13:2022-11-012022-11-01
CVE-2022-20447 CVE-2022-20447: In PAN_WriteBuf of pan_api In PAN_WriteBuf of pan_api.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0016P4UNKNOWN≥ 13:0, < 13:2024-01-01≥ 14:0, < 14:2024-01-012024-01-01
CVE-2024-0016 CVE-2024-0016: In multiple locations, there is a possible out of bounds read due to a missing bounds check In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20468P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20468 CVE-2022-20468: In BNEP_ConnectResp of bnep_api In BNEP_ConnectResp of bnep_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0030P4UNKNOWN≥ 14-next:0, < 14-next:2024-02-01≥ 13:0, < 13:2024-02-01+1 more2024-02-01
CVE-2024-0030 CVE-2024-0030: In btif_to_bta_response of btif_gatt_util In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
Platform Packages Modules Bluetooth vulnerabilities | cvebase