CVE-2023-40088: Use After Free
Published Dec 4, 2023
·Updated
In callback_thread_event of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible memory corruption due to a use after free. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
6 affected components
Google Android
Google Android=11.0
Google Android=12.0
Google Android=12.1
Google Android=13.0
Google Android=14.0
Remediation
Patch Available
Event History
Dec 4, 2023
CVE Published
via Android·12:00 AM
News Published
07:37 PM
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40088.
2
What is the severity of CVE-2023-40088?
CVE-2023-40088 has a severity rating of critical.
3
What software is affected by CVE-2023-40088?
The software affected by CVE-2023-40088 is Google Android.
4
Is user interaction required for exploitation of CVE-2023-40088?
No, user interaction is not needed for exploitation of CVE-2023-40088.
5
Are there any references for CVE-2023-40088?
Yes, you can find references for CVE-2023-40088 at the following links: [1](https://source.android.com/security/bulletin/2023-12-01) and [2](https://source.android.com/docs/security/bulletin/2023-12-01).