Description
In btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Elevation of privilege
Product status
12L
12
References
android.googlesource.com/...1deb331ff5e5849388fa92ee4c40f979
source.android.com/security/bulletin/2025-03-01