{"id":"CVE-2025-48593","title":"In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free","summary":"In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"google","product":"android","affected":["android = 13.0","android = 14.0","android = 15.0","android = 16.0"],"published":"2025-11-18","updated":"2026-09-26","sourceUpdated":"2026-09-26T00:10:00.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-48593","references":[{"url":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/5ed63461b44198c80d5aff7e1af1df812f782abb","label":"security@android.com"},{"url":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/c69c78d7c4f623201f35831d32e6c401156e76cc","label":"security@android.com"},{"url":"https://source.android.com/security/bulletin/2025-11-01","label":"security@android.com"}],"tags":["nvd","exploit-available"],"epss":0.00894,"epssPercentile":0.57801,"exploits":{"github":4,"githubRepos":["https://github.com/zhuowei/blueshrimp","https://github.com/logesh-GIT001/CVE-2025-48593","https://github.com/ranasen-rat/CVE-2025-48593"],"checkedAt":"2026-09-26T00:23:14.513Z"},"exploitAvailable":true,"ingestedAt":"2026-09-26T00:22:39.976Z","slug":"CVE-2025-48593","body":"## Overview\n\nIn bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.\n\n## Affected\n\n- `android = 13.0`\n- `android = 14.0`\n- `android = 15.0`\n- `android = 16.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":56,"depthScoreParts":{"impact":44,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[]}