interesting · Bluetooth — mobile
Google says a malformed Android Bluetooth storage value can corrupt the heap and reach remote code execution.
Affects
Android's privileged Bluetooth service on Android 16, Android 16 QPR2, and Android 17 devices.
The defect is a heap out-of-bounds write in cfg2prop inside the privileged Bluetooth component, and Google classifies the result as remote code execution without user interaction.
Detail and 2 sources
The missing fact is the attacker’s starting position: the bulletin does not identify the transport, profile, pairing state, or privileges retained after execution.
Chain to watch
Supply a malformed value that reaches cfg2prop.→↓Trigger a heap out-of-bounds write in the privileged Bluetooth component.→↓Reach the remote-code-execution consequence described by Google.→↓The initiating Bluetooth route and post-exploitation boundary are unpublished.
Unverified chainMap the affected caller from the fix and reproduce it while recording transport, pairing state, process identity, and SELinux domain.