In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143894715
Threat-Mapped Scoring
Score: 1.8
Priority: P4 - Informational (Low)
S9 – Sabotage of System/App
EPSS
Score: 0.13415Percentile:
0.93866
CVSS Scoring
CVSS v3.1 Score: 8.8
Severity: HIGH
Mapped CWE(s)
CWE-682
: Incorrect Calculation
All CAPEC(s)
CAPEC-128 : Integer Attacks
CAPEC-129 : Pointer Manipulation
CAPEC(s) with Mapped TTPs
Mapped ATT&CK TTPs
Affected Products
cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_20_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_20_x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p_smart_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p_smart_2019_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p20_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p30_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:y6_2019_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:y6_pro_2019_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:y9_2019_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:nova_3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:nova_lite_3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:honor_8a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:honor_8x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:honor_view_20_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_30_pro_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_30_pro_5g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:huawei:mate_30_5g_firmware:*:*:*:*:*:*:*:*
← Back to Home
BrownCoat Threat Intelligence Platform | 2025 Steve Gray — You Can’t Take the Sky from Me