As the tech giant, Google has provided a detailed breakdown on the android security bulletin website.
Another critical vulnerability related to OpenSSL and BoringSSL can also be activated with a specially crafted file.
As the security bugs are present in different libraries, services, and implementation of Bluetooth Framework API.

Moreover, there is currently no information available on the active exploitation of the vulnerabilities patched by the hackers.

