CVE-2025-48593High· 8.0▾ MidnightPoC availableIn bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
4 GitHub repos (last check)
In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
android = 13.0android = 14.0android = 15.0android = 16.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-0163Critical· 9.8In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free
CVE-2026-58751Medium· 6.7In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code
CVE-2026-58724High· 7.0In multiple locations, there is a possible use-after-free due to a race condition
CVE-2026-56988Medium· 6.4In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition
CVE-2026-21102Medium· 6.7Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.
CVE-2026-58704High· 8.8In Cellular Modem, there is a possible permission bypass due to a logic error in the code