Description
In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Remote code execution
Product status
15
References
android.googlesource.com/...c1aa8dfa8e5524858d47f6a80b765fa4
source.android.com/security/bulletin/2025-03-01