CVE-2023-21195

MEDIUM

Google Android - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

In btm_ble_periodic_adv_sync_tx_rcvd of btm_ble_gap.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure over Bluetooth, if the firmware were compromised with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-233879420

References (1)

Core 1

Scores

CVSS v3 4.5
EPSS 0.0004
EPSS Percentile 12.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-125
Status published
Products (1)
google/android 13.0
Published Jun 28, 2023
Tracked Since Feb 18, 2026