CVE-2023-35657 Details
Description
In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
A type confusion issue in the Bluetooth Fluoride module can lead to a potential out-of-bounds read. This vulnerability, located in the 'bta_av_config_ind' function of 'bta_av_aact.cc', could result in local information disclosure without requiring additional execution privileges or user interaction for exploitation.
Users can update to the latest version of Android, as security patch levels of 2025-05-01 or later address this vulnerability. For devices on Android 10 and later, the Google Play system update can also be used to apply this patch.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google android | 13.0 14.0 15.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 5, 2025 | Initial Analysis | [email protected] |
| Sep 4, 2025 | CVE Modified | CISA-ADP |
| Sep 4, 2025 | New CVE Received | [email protected] |