ThreatCluster

Multiple Bluetooth Vulnerabilities Addressed in Recent Microsoft Updates

First seen 9 Dec 2025, 10:52 UTC Api.Msrc.Microsoft 48

Article Content

Browse articles
ThreatCluster

Microsoft has published information on two critical Bluetooth vulnerabilities: CVE-2025-40309 and CVE-2025-39981. The first vulnerability involves a use-after-free (UAF) issue in the SCO connection handling, while the second addresses possible UAFs in the MGMT protocol. Affected systems include those utilizing Bluetooth technology.