CVE-2025-22412

All FrameworksAndroidCWE-416CVE-2025-22412

CVE-2025-22412

State: PUBLISHED · Published: 2025-08-26 · Updated: 2026-02-26 · Assigner: google_android
Description
In multiple functions of sdp_server.cc, there is a possible use after free due to a logic error in the code. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/22xxx/CVE-2025-22412.json