CVE-2023-40088: Use After Free
In callbackthreadevent of comandroidbluetoothbtserviceAdapterService.cpp, there is a possible memory corruption due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40088.
What is the severity of CVE-2023-40088?
CVE-2023-40088 has a severity rating of critical.
What software is affected by CVE-2023-40088?
The software affected by CVE-2023-40088 is Google Android.
Is user interaction required for exploitation of CVE-2023-40088?
No, user interaction is not needed for exploitation of CVE-2023-40088.
Are there any references for CVE-2023-40088?
Yes, you can find references for CVE-2023-40088 at the following links: [1](https://source.android.com/security/bulletin/2023-12-01) and [2](https://source.android.com/docs/security/bulletin/2023-12-01).