In onremoveisodatapath of btmisoimpl.h, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "match_only_versions": [ "13-next" ], "digest": { "threshold": 0.9, "line_hashes": [ "153701393712277260550700188059929756340", "251818851799605668994965379096955928319", "334342765385893153876513582921359902381" ] }, "id": "PUB-A-236688764-dd54dabf", "source": "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/1a8a5ece61c63560da589d36ed6597de73a5bb1a", "deprecated": false, "signature_version": "v1", "target": { "file": "system/stack/btm/btm_iso_impl.h" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Bluetooth/+/1a8a5ece61c63560da589d36ed6597de73a5bb1a" ], "spl": "2023-06-01", "severity": "Moderate", "types": [ "ID" ] }