Technical triage of Android's April 2026 release addressing zero-click Bluetooth HCI fragmentation heap buffer overflows.
| CVE 编号 | 核心子系统 / 组件 | 影响程度 | CVSS | 是否在野利用? |
|---|---|---|---|---|
| CVE-2024-0044 | Fluoride Bluetooth Stack | Heap Buffer Overflow / RCE | 8.8 High | YES (In-The-Wild) |
| CVE-2024-0045 | Android Wi-Fi Service | Information Disclosure | 6.5 Medium | No |
| CVE-2024-0046 | Sensors HAL | Denial of Service | 5.1 Medium | No |
Inspect the C commit in system/bt/stack/l2cap showing packet length assertion checks during ACL fragment reassembly.