CVE-2023-21125

HIGH

Google Android - Use After Free

Title source: rule
STIX 2.1

Description

In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.

Exploits (1)

nomisec WORKING POC
by 761669642 · poc
https://github.com/761669642/Mahesh-970-CVE-2023-21125_bluedriod_repo

Scores

CVSS v3 8.0
EPSS 0.0012
EPSS Percentile 30.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (2)
google/android 12.0
google/android 12.1
Published Aug 26, 2025
Tracked Since Feb 18, 2026