CVE-2025-48571Medium· 4.3▾ SunlitIn multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. Use…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
android = 17.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-0017High· 7.7In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the code
CVE-2026-0019High· 7.8In SettingsLib, there is a possible way to disable system components due to a logic error in the code
CVE-2026-58766High· 7.8In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-0186Medium· 6.7In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-0187Medium· 6.7In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code
CVE-2026-0189High· 8.4In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code