Remote code execution via Bluetooth SDP use-after-free
Published Nov 18, 2025 · Updated Nov 18, 2025
Use-after-free in Android 13 through 16 Bluetooth code allows remote attackers to execute code over an adjacent Bluetooth connection. The bta_hf_client_cb_init function reinitializes an HF client control block without canceling an existing SDP search, allowing overlapping discovery callbacks to free a new p_disc_db while the SDP layer retains and later reads it. Exploitation requires Bluetooth proximity, prior pairing, and a device with the Hands-Free client profile enabled; the demonstrated public proof of concept crashes the Bluetooth process on an Android Automotive emulator.
Summary
What happened
Use-after-free in Android 13 through 16 Bluetooth code allows remote attackers to execute code over an adjacent Bluetooth connection. The bta_hf_client_cb_init function reinitializes an HF client control block without canceling an existing SDP search, allowing overlapping discovery callbacks to free a new p_disc_db while the SDP layer retains and later reads it. Exploitation requires Bluetooth proximity, prior pairing, and a device with the Hands-Free client profile enabled; the demonstrated public proof of concept crashes the Bluetooth process on an Android Automotive emulator.
The record
- CVE
- CVE-2025-48593
- Published
- Nov 18, 2025
- Updated
- Nov 18, 2025
- Vendor
- Go standard library
- Product
- Android
- Classifications
- CWE-416, T1203
- Attack vector
- adjacent
- Privileges
- authenticated
Timeline
How it unfolded
- Nov 18, 2025CVE publishedPublication date reported by the CVE source.
- Nov 18, 2025Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=13
- Affected versionversion=14
- Affected versionversion=15
- Affected versionversion=16
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- blueshrimpproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo