Junglewise Threat Intelligence

CVE-2025-48571: Google Android information disclosure in btm_sec.cc

CVE-2025-48571 · Severity: medium · CVSS 4.3 · Published 2026-06-17

Technologies: Google Android. Vendors: Google.

Executive brief

A logic error in the Android operating system's Bluetooth security component could allow a remote attacker to intercept SMS messages. To exploit this, an attacker would need to trick a user into performing a specific interaction. If successful, this could lead to the unauthorized disclosure of private text messages and sensitive information.

Technical details

A logic error exists within multiple functions of the 'btm_sec.cc' component in the Android Bluetooth stack. This vulnerability is classified as a protection mechanism failure (CWE-693) that allows for remote information disclosure. An attacker can exploit this flaw to intercept SMS messages without requiring additional execution privileges, though user interaction is a prerequisite for a successful attack. The issue is addressed in Android 17 with security patch levels of 2026-07-01 or later.

Affected products

  • Google Android 17

Timeline

  • 2026-06-16: advisory: Android 17 Security Release Notes published
  • 2026-06-17: disclosed: NVD publication date

References

Related threats