Platform Packages Modules Bluetooth vulnerabilities
119 known vulnerabilities affecting platform/packages_modules_bluetooth.
Total CVEs
119
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
UNKNOWN119
Vulnerabilities
Page 4 of 6
CVE-2023-20985P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-20985 CVE-2023-20985: In BTA_GATTS_HandleValueIndication of bta_gatts_api
In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20936P3UNKNOWN≥ 13-next:0, < 13-next:2023-03-01≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-20936 CVE-2023-20936: In bta_av_rc_disc_done of bta_av_act
In bta_av_rc_disc_done of bta_av_act.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20967P3UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 13:0, < 13:2023-04-012023-04-01
CVE-2023-20967 CVE-2023-20967: In avdt_scb_hdl_pkt_no_frag of avdt_scb_act
In avdt_scb_hdl_pkt_no_frag of avdt_scb_act.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-45866P3UNKNOWN≥ 14-next:0, < 14-next:2023-12-05≥ 13:0, < 13:2023-12-05+1 more2023-12-01
CVE-2023-45866 CVE-2023-45866: In multiple locations, there is a possible way to inject keystrokes due to improper input validation
In multiple locations, there is a possible way to inject keystrokes due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20547P3UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20547 CVE-2022-20547: In multiple functions of AdapterService
In multiple functions of AdapterService.java, there is a possible way to manipulate Bluetooth state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20207P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-012022-06-01
CVE-2022-20207 CVE-2022-20207: In TBD of GattDebugUtils
In TBD of GattDebugUtils.java, there is a possible permission bypass due to accidentally enabling debug_admin . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35666P3UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 13:0, < 13:2023-09-012023-09-01
CVE-2023-35666 CVE-2023-35666: In bta_av_rc_msg of bta_av_act
In bta_av_rc_msg of bta_av_act.cc, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20461P3UNKNOWN≥ 13:0, < 13:2023-01-012023-01-01
CVE-2022-20461 CVE-2022-20461: In pinReplyNative of com_android_bluetooth_btservice_AdapterService
In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to type confusion. This could lead to local escalation of privilege of BLE with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-40090P3UNKNOWN≥ 13:0, < 13:2023-12-01≥ 14:0, < 14:2023-12-012023-12-01
CVE-2023-40090 CVE-2023-40090: In BTM_BleVerifySignature of btm_ble
In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26441P3UNKNOWN≥ 16-next:0, < 16-next:2025-06-01≥ 15:0, < 15:2025-06-01+2 more2025-06-01
CVE-2025-26441 CVE-2025-26441: In add_attr of sdp_discovery
In add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20126P3UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-012022-06-01
CVE-2022-20126 CVE-2022-20126: In setScanMode of AdapterService
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-0092P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 15:0, < 15:2025-03-01+2 more2025-03-01
CVE-2025-0092 CVE-2025-0092: In handleBondStateChanged of AdapterService
In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-24023P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+2 more2025-09-01
CVE-2023-24023 CVE-2023-24023: In multiple locations, there is a possible way to impersonate and MitM a device across session by only compromising one session key due to an insecure
In multiple locations, there is a possible way to impersonate and MitM a device across session by only compromising one session key due to an insecure protocol design on Bluetooth Legacy Secure Connection (LSC). This could lead to remote escalation of privilege with no additional execution privileges needed. User int
osv
CVE-2024-0045P4UNKNOWN≥ 14-next:0, < 14-next:2024-03-01≥ 13:0, < 13:2024-03-01+1 more2024-03-01
CVE-2024-0045 CVE-2024-0045: In smp_proc_sec_req of smp_act
In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43766P4UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2026-03-01≥ 15:0, < 15:2026-03-01+2 more2026-03-01
CVE-2024-43766 CVE-2024-43766: In multiple functions of btm_ble_sec
In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22407P4UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 15:0, < 15:2025-03-012025-03-01
CVE-2025-22407 CVE-2025-22407: In hidd_check_config_done of hidd_conn
In hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20447P4UNKNOWN≥ 13:0, < 13:2022-11-012022-11-01
CVE-2022-20447 CVE-2022-20447: In PAN_WriteBuf of pan_api
In PAN_WriteBuf of pan_api.cc, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0016P4UNKNOWN≥ 13:0, < 13:2024-01-01≥ 14:0, < 14:2024-01-012024-01-01
CVE-2024-0016 CVE-2024-0016: In multiple locations, there is a possible out of bounds read due to a missing bounds check
In multiple locations, there is a possible out of bounds read due to a missing bounds check. This could lead to paired device information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20468P4UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20468 CVE-2022-20468: In BNEP_ConnectResp of bnep_api
In BNEP_ConnectResp of bnep_api.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-0030P4UNKNOWN≥ 14-next:0, < 14-next:2024-02-01≥ 13:0, < 13:2024-02-01+1 more2024-02-01
CVE-2024-0030 CVE-2024-0030: In btif_to_bta_response of btif_gatt_util
In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv