CVE-2025-48593
In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code...
- Published
- Nov 18, 2025
- Updated
- Feb 26, 2026
- Assigning CNA
- google_android
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 57.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Sources
4- Blackash-CVE-2025-48593Research
CVE-2025-48593
- CVE-2025-48593Research
"A single malicious packet can own your device." — Android Security Team, Nov 2025
- CVE-2025-48593Research
Technical analysis of a critical zero-click remote code execution vulnerability (CVE-2025-48593) affecting Android 13-16, detailing root cause, exploitation flow, and mitigation strategies.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.