CVE-2025-0079

In multiple locations, there is a possible way that avdtp and avctp channels could be unencrypted due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*

History

02 Sep 2025, 18:05

Type Values Removed Values Added
CPE cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:15.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:14.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:*
References () https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b1e6d8d1e393d246a0738c92747a0bef98e67a30 - () https://android.googlesource.com/platform/packages/modules/Bluetooth/+/b1e6d8d1e393d246a0738c92747a0bef98e67a30 - Product
References () https://source.android.com/security/bulletin/2025-03-01 - () https://source.android.com/security/bulletin/2025-03-01 - Vendor Advisory
First Time Google
Google android

27 Aug 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) En varias ubicaciones, es posible que los canales avdtp y avctp no estén cifrados debido a un error lógico en el código. Esto podría provocar una escalada local de privilegios, requiriendo privilegios de ejecución del usuario. La interacción del usuario no es necesaria para la explotación.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-250

26 Aug 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-26 23:15

Updated : 2025-09-02 18:05


NVD link : CVE-2025-0079

Mitre link : CVE-2025-0079

CVE.ORG link : CVE-2025-0079


JSON object : View

Products Affected

google

  • android
CWE
CWE-250

Execution with Unnecessary Privileges