{"id":"ASB-A-282234870","details":"In CreateAudioBroadcast of broadcaster.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-282234870","CVE-2023-45776"],"modified":"2026-04-30T15:48:46.890647Z","published":"2023-12-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2023-12-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/8e3b3fc918b3ea77754c6d82ab0f09cce81e145b"}],"affected":[{"package":{"name":"platform/packages/modules/Bluetooth","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14-next:0"},{"fixed":"14-next:2023-12-01"}]}],"versions":["14-next"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-282234870-8690136a","target":{"file":"system/bta/le_audio/broadcaster/broadcaster.cc"},"source":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/5f9059acdfed500ea5ff4b159795280d5fa2ecbf","digest":{"threshold":0.9,"line_hashes":["142684289885384697536288631086263826842","16406206357247479788666354731309863657","286905061467636589645434065539620543548","100785283712054938349270543023197146987","43855841289177912729581738001999468354","16406206357247479788666354731309863657","13976835086402222212545783096397724990","284047784408702917118367082191050182332"]},"deprecated":false,"signature_version":"v1","signature_type":"Line"}],"types":["EoP"],"severity":"High","fixes":["https://android.googlesource.com/platform/packages/modules/Bluetooth/+/5f9059acdfed500ea5ff4b159795280d5fa2ecbf"],"spl":"2023-12-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-282234870.json"}},{"package":{"name":"platform/packages/modules/Bluetooth","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14:0"},{"fixed":"14:2023-12-01"}]}],"versions":["14"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-282234870-898735a2","target":{"file":"system/bta/le_audio/broadcaster/broadcaster.cc"},"source":"https://android.googlesource.com/platform/packages/modules/Bluetooth/+/5f9059acdfed500ea5ff4b159795280d5fa2ecbf","digest":{"threshold":0.9,"line_hashes":["142684289885384697536288631086263826842","16406206357247479788666354731309863657","286905061467636589645434065539620543548","100785283712054938349270543023197146987","43855841289177912729581738001999468354","16406206357247479788666354731309863657","13976835086402222212545783096397724990","284047784408702917118367082191050182332"]},"deprecated":false,"signature_version":"v1","signature_type":"Line"}],"types":["EoP"],"severity":"High","fixes":["https://android.googlesource.com/platform/packages/modules/Bluetooth/+/5f9059acdfed500ea5ff4b159795280d5fa2ecbf"],"spl":"2023-12-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-282234870.json"}}],"schema_version":"1.7.5"}