Description
In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-10-06
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a use‑after‑free bug in Android’s Bluetooth handler. A logic error can cause the callback to reference freed memory, letting an attacker execute arbitrary code. The flaw grants full code‑execution capability without requiring any privilege escalation and does not need the victim to interact with the device.

Affected Systems

Google Android devices that implement the affected Bluetooth firmware. No specific version information is supplied, so all Android platforms using this Bluetooth stack are potentially impacted.

Risk and Exploitability

The CVSS score is not listed, but the risk is high due to the nature of the flaw: remote code execution with no privilege escalation and no user interaction required. The EPSS score is unavailable, and the vulnerability is not currently in the CISA KEV catalog, suggesting it may not yet have seen widespread exploitation. Nevertheless, the attack vector is likely via an active Bluetooth connection, enabling an adversary to trigger the logic error from a remote device. Attackers could potentially run malicious code in the context of the Android system process that owns the Bluetooth stack.

Generated by OpenCVE AI on October 6, 2026 at 19:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Disable Bluetooth when it is not needed to eliminate the attack surface.
  • Apply any Android security patch that resolves the use‑after‑free bug as soon as it becomes available.
  • Configure the device to block or restrict untrusted Bluetooth connections, such as using device security settings or a trusted‑list policy.

Generated by OpenCVE AI on October 6, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
Description In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-10-06T20:19:39.319Z

Reserved: 2026-06-16T17:51:15.419Z

Link: CVE-2026-55330

cve-icon Vulnrichment

Updated: 2026-10-06T18:56:28.287Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:14.810

Modified: 2026-10-06T21:17:20.823

Link: CVE-2026-55330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T19:45:04Z

Weaknesses