Skip to finding
interesting · Bluetooth — mobile

Google says a malformed Android Bluetooth storage value can corrupt the heap and reach remote code execution.

Affects

Android's privileged Bluetooth service on Android 16, Android 16 QPR2, and Android 17 devices.

The defect is a heap out-of-bounds write in cfg2prop inside the privileged Bluetooth component, and Google classifies the result as remote code execution without user interaction.

Detail and 2 sources

The missing fact is the attacker’s starting position: the bulletin does not identify the transport, profile, pairing state, or privileges retained after execution.

Chain to watch
Supply a malformed value that reaches cfg2prop.→↓Trigger a heap out-of-bounds write in the privileged Bluetooth component.→↓Reach the remote-code-execution consequence described by Google.→↓The initiating Bluetooth route and post-exploitation boundary are unpublished.
Unverified chainMap the affected caller from the fix and reproduce it while recording transport, pairing state, process identity, and SELinux domain.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, October 6, 2026