CVE-2025-26438 | Google Android 13/14/15 SMP smp_act.cc smp_process_secure_connection_oob_data improper authentication (EUVD-2025-26867)
A vulnerability identified as critical has been detected in Google Android 13/14/15. Affected by this vulnerability is the function smp_process_secure_connection_oob_data of the file smp_act.cc of the component SMP. This manipulation causes improper authentication.
This vulnerability is tracked as CVE-2025-26438. The attack is possible to be carried out remotely. No exploit exists.
Applying a patch is the recommended action to fix this issue.