CVE-2023-40090
MEDIUMAndroid - Remote Privilege Escalation via BTM_BleVerifySignature Side Channel
Title source: llmDescription
In BTM_BleVerifySignature of btm_ble.cc, there is a possible way to bypass signature validation due to side channel information disclosure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References (2)
Core 2
Core References
Mailing List, Patch
https://android.googlesource.com/platform/packages/modules/Bluetooth/+/495417bd068c35de0729d9a332639bd0699153ff
Patch, Third Party Advisory
https://source.android.com/security/bulletin/2023-12-01
Scores
CVSS v3
6.5
EPSS
0.0054
EPSS Percentile
41.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-203
Status
published
Products (5)
google/android
11.0
google/android
12.0
google/android
12.1
google/android
13.0
google/android
14.0
Published
Dec 04, 2023
Tracked Since
Feb 18, 2026