CVE-2023-21125
8.0Google · Android
A use after free vulnerability in the Bluetooth stack of Android 12 and 12L could allow a local attacker to escalate privileges.
Executive summary
A use after free memory corruption flaw in the Android Bluetooth stack allows for local privilege escalation without user interaction.
Vulnerability
This vulnerability exists within the btif_hh_hsdata_rpt_copy_cb function of the bta_hh.cc component. It allows a local attacker to corrupt memory via a use after free, resulting in an elevation of privilege over Bluetooth.
Business impact
Successful exploitation allows an attacker to gain elevated privileges on a targeted device, potentially leading to unauthorized access to sensitive user data and system settings. Given the CVSS score of 8.0, this represents a high-severity risk that could compromise the integrity and confidentiality of the entire mobile device environment.
Remediation
Immediate Action: Apply the security updates provided in the March 2025 Android Security Bulletin to patch the affected Bluetooth subsystem.
Proactive Monitoring: Monitor device Bluetooth logs for unexpected service restarts or anomalous crash reports that may indicate exploitation attempts.
Compensating Controls: Disable Bluetooth functionality when not in use to reduce the attack surface available to nearby adversaries.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
This vulnerability presents a significant risk to Android users by enabling privilege escalation through the Bluetooth stack. Organizations and individual users should prioritize the installation of the March 2025 Android security patches to effectively mitigate this memory corruption issue and prevent potential unauthorized system access.