Vulnerability Intelligence Report
CVE-2025-48593
In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
No Active Exploit Signals
CVSS Base Score
8.0
HIGH
Exploitability:2.1
Impact Score:5.9
EPSS Probability:0.91%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-416 ↗CWE-416 Use After Free
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Android | 16 (affected), 15 (affected), 14 (affected), 13 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.911%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Android (associated with Google Inc. or Open Handset Alliance) · Vendor · USA |
| Reserved | 2025-05-22T18:12:07 |
| Published | 2025-11-18T04:51:57 |
| Last Updated | 2026-02-26T16:56:47 |
Community Chatter & Buzz