Executive brief
A security vulnerability exists in the Android operating system's Bluetooth discovery component. This flaw could allow a nearby attacker to execute malicious code on a user's device without any interaction from the user. Such an attack could lead to a complete compromise of the device, including unauthorized access to personal data and system functions.
Technical details
A heap buffer overflow vulnerability exists in multiple functions within 'sdp_discovery.cc', a component of the Android Bluetooth stack responsible for Service Discovery Protocol (SDP) operations. The flaw is triggered during the processing of SDP discovery responses. An attacker within Bluetooth range (proximal/adjacent) can exploit this by sending specially crafted packets, leading to memory corruption. Successful exploitation allows for remote code execution (RCE) in the context of the Bluetooth process without requiring any execution privileges or user interaction. The issue is addressed in the June 2026 Android Security Bulletin with security patch levels of 2026-06-05 or later.
Affected products
- Google Android 14, 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin and NVD.
- 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.