PT-2025-36040 · Unknown · Localbluetoothlebroadcast.Java

Published

2025-09-01

·

Updated

2025-09-05

·

CVE-2025-32330

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LocalBluetoothLeBroadcast.java (affected versions not specified)
Description An issue exists in the generateRandomPassword function of LocalBluetoothLeBroadcast.java that may allow interception of the Auracast audio stream due to an insecure default value. This could lead to remote information disclosure without requiring additional execution privileges or user interaction.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ASB-A-389127608
BDU:2025-11690
CVE-2025-32330

Affected Products

Localbluetoothlebroadcast.Java