Description
In avrc_vendor_msg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Elevation of privilege
Product status
14
13
References
android.googlesource.com/...1d0faf4658bb3ba6ea7f77d4d4a5e1b1
source.android.com/security/bulletin/2025-09-01