In avrcvendormsg of avrc_opt.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "signature_type": "Function", "deprecated": false, "digest": { "length": 813.0, "function_hash": "161964072447301556907021949801306052708" }, "signature_version": "v1", "target": { "file": "system/stack/avrc/avrc_opt.cc", "function": "avrc_vendor_msg" }, "id": "ASB-A-271962784-019302b8", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d5de235b461ec83e43a7db513e286d3204c4cedf" }, { "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "233173819388143007683002944958412463167", "281597275017415760895749258884319544714", "222957863068205357447326730381878078511", "250779556980860033012007924240257078315", "321543060838153475417302785315600971957" ] }, "signature_version": "v1", "target": { "file": "system/stack/avrc/avrc_opt.cc" }, "id": "ASB-A-271962784-d308274d", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d5de235b461ec83e43a7db513e286d3204c4cedf" } ], "types": [ "EoP" ], "severity": "High", "spl": "2025-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d5de235b461ec83e43a7db513e286d3204c4cedf" ] }
{ "vanir_signatures": [ { "signature_type": "Function", "deprecated": false, "digest": { "length": 813.0, "function_hash": "161964072447301556907021949801306052708" }, "signature_version": "v1", "target": { "file": "system/stack/avrc/avrc_opt.cc", "function": "avrc_vendor_msg" }, "id": "ASB-A-271962784-ae038f9f", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d5de235b461ec83e43a7db513e286d3204c4cedf" }, { "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "233173819388143007683002944958412463167", "281597275017415760895749258884319544714", "222957863068205357447326730381878078511", "250779556980860033012007924240257078315", "321543060838153475417302785315600971957" ] }, "signature_version": "v1", "target": { "file": "system/stack/avrc/avrc_opt.cc" }, "id": "ASB-A-271962784-b403dfc1", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d5de235b461ec83e43a7db513e286d3204c4cedf" } ], "types": [ "EoP" ], "severity": "High", "spl": "2025-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d5de235b461ec83e43a7db513e286d3204c4cedf" ] }
{ "vanir_signatures": [ { "signature_type": "Function", "deprecated": false, "digest": { "length": 813.0, "function_hash": "161964072447301556907021949801306052708" }, "signature_version": "v1", "target": { "file": "system/stack/avrc/avrc_opt.cc", "function": "avrc_vendor_msg" }, "id": "ASB-A-271962784-44b032d0", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d5de235b461ec83e43a7db513e286d3204c4cedf" }, { "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "233173819388143007683002944958412463167", "281597275017415760895749258884319544714", "222957863068205357447326730381878078511", "250779556980860033012007924240257078315", "321543060838153475417302785315600971957" ] }, "signature_version": "v1", "target": { "file": "system/stack/avrc/avrc_opt.cc" }, "id": "ASB-A-271962784-cea561e7", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d5de235b461ec83e43a7db513e286d3204c4cedf" } ], "types": [ "EoP" ], "severity": "High", "spl": "2025-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/d5de235b461ec83e43a7db513e286d3204c4cedf" ] }