Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-55330: Google Android Bluetooth component allows remote code execution
CVE-2026-55330 · published 9 days ago
Summary
A flaw in Android’s Bluetooth handling code can let an attacker run their own program on the device without any user interaction. The problem occurs when the system mistakenly releases memory that it later still uses, opening a path for remote code execution. Install the latest Android security updates or patches to fix the issue.
What to do
- Update google :unknown: to version Pixel-family specific:2026-10-05.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Android | :unknown: |
>= Pixel-family specific:0, < Pixel-family specific:2026-10-05 Fix: upgrade to Pixel-family specific:2026-10-05
|
|
| – | android | Android kernel |
Original advisory text
PUB-A-522372636
In BluetoothCccHandlerCallbackImpl of bluetooth_ccc.cc, there is a possible use-after-free due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-416Use After Free
Timeline
Published1 Oct 2026
Updated9 Oct 2026
First seen5 Oct 2026
Track software like this
Free during beta