CVE-2025-32330
BaseFortify
Publication date: 2025-09-04
Last updated on: 2025-09-08
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| android | 13.0 | |
| android | 14.0 | |
| android | 15.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1188 | The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the generateRandomPassword function of LocalBluetoothLeBroadcast.java, where an insecure default value allows the Auracast audio stream to be intercepted. This means that an attacker nearby could potentially access the audio stream without needing any special permissions or user interaction.
How can this vulnerability impact me? :
The vulnerability could lead to remote information disclosure of the Auracast audio stream to an attacker in close proximity. This could compromise the confidentiality of audio data being transmitted, potentially exposing sensitive information without the user's knowledge or consent.