CVE-2025-48593 Details
Description
In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
A remote code execution vulnerability has been identified in the Android Bluetooth stack, specifically within the Hands-Free Client (HFC) module. This issue arises from a use-after-free error in the HFC callback initialization function, which can be exploited to execute arbitrary code remotely. Notably, this vulnerability does not require any additional privileges or user interaction for exploitation.
Users can update to the November 2025 security patch level, which addresses this vulnerability. Device manufacturers should include this update and set the security patch level to 2025-11-01.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google android | 13.0 14.0 15.0 16.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 19, 2025 | Initial Analysis | [email protected] |
| Nov 18, 2025 | CVE Modified | CISA-ADP |
| Nov 18, 2025 | New CVE Received | [email protected] |