CVE-2015-6618: Google Android

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Bluetooth in Android 4.4 and 5.x before 5.1.1 LMY48Z allows user-assisted remote attackers to execute arbitrary code by leveraging access to the local physical environment, aka internal bug 24595992.

Affected products

  • Google Android: version 4.4 only; version 5.0 only; version 5.1 only

Published 2015-12-08. Last modified 2026-06-17.