In avdtmsgind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "69968497529221303174354349176262428972", "289267339819583124441987779324406424110", "210875894870981578955181235640352806598", "232881515703603029002002586106176935855", "298765360413203219284747084932649921103" ] }, "id": "ASB-A-273995284-a77d54bd", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6012433653b2770ddb67f5d6e9042e8ff6f8d66c", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/avdt/avdt_msg.cc" }, "signature_type": "Line" }, { "digest": { "length": 3611.0, "function_hash": "101213322258309175509044928261249359797" }, "id": "ASB-A-273995284-d749451d", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6012433653b2770ddb67f5d6e9042e8ff6f8d66c", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/avdt/avdt_msg.cc", "function": "avdt_msg_ind" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/6012433653b2770ddb67f5d6e9042e8ff6f8d66c", "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/ca504bbacbdb2478cf18103c28ca39915bc352f6" ], "spl": "2025-04-01", "severity": "High", "types": [ "EoP" ] }