Platform Packages Apps Bluetooth vulnerabilities
17 known vulnerabilities affecting platform/packages_apps_bluetooth.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN17
Vulnerabilities
Page 1 of 1
CVE-2025-0092UNKNOWN≥ 12:0, < 12:2025-03-01≥ 12L:0, < 12L:2025-03-012025-03-01
CVE-2025-0092 CVE-2025-0092: In handleBondStateChanged of AdapterService
In handleBondStateChanged of AdapterService.java, there is a possible permission bypass due to misleading or insufficient UI. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-0093UNKNOWN≥ 12:0, < 12:2025-03-01≥ 12L:0, < 12L:2025-03-012025-03-01
CVE-2025-0093 CVE-2025-0093: In handleBondStateChanged of AdapterService
In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-34730UNKNOWN≥ 12:0, < 12:2025-01-01≥ 12L:0, < 12L:2025-01-012025-01-01
CVE-2024-34730 CVE-2024-34730: In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code
In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-34719UNKNOWN≥ 12:0, < 12:2024-11-01≥ 12L:0, < 12L:2024-11-012024-11-01
CVE-2024-34719 CVE-2024-34719: In multiple locations, there is a possible permissions bypass due to a missing null check
In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20467UNKNOWN≥ 11:0, < 11:2023-03-01≥ 12:0, < 12:2023-03-01+1 more2023-03-01
CVE-2022-20467 CVE-2022-20467: In isBluetoothShareUri of BluetoothOppUtility
In isBluetoothShareUri of BluetoothOppUtility.java, there is a possible incorrect file read due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20133UNKNOWN≥ 10:0, < 10:2022-06-01≥ 11:0, < 11:2022-06-01+2 more2022-06-01
CVE-2022-20133 CVE-2022-20133: In setDiscoverableTimeout of AdapterService
In setDiscoverableTimeout of AdapterService.java, there is a possible bypass of user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20126UNKNOWN≥ 10:0, < 10:2022-06-01≥ 11:0, < 11:2022-06-01+2 more2022-06-01
CVE-2022-20126 CVE-2022-20126: In setScanMode of AdapterService
In setScanMode of AdapterService.java, there is a possible way to enable Bluetooth discovery mode without user interaction due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20207UNKNOWN≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20207 CVE-2022-20207: In TBD of GattDebugUtils
In TBD of GattDebugUtils.java, there is a possible permission bypass due to accidentally enabling debug_admin . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1017UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1017 CVE-2021-1017: In AdapterService and GattService definition of AndroidManifest
In AdapterService and GattService definition of AndroidManifest.xml, there is a possible way to disable bluetooth connection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-1006UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1006 CVE-2021-1006: In several functions of DatabaseManager
In several functions of DatabaseManager.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0604UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-01+2 more2021-07-01
CVE-2021-0604 CVE-2021-0604: In generateFileInfo of BluetoothOppSendFileInfo
In generateFileInfo of BluetoothOppSendFileInfo.java, there is a possible way to share private files over Bluetooth due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0588UNKNOWN≥ 8.1:0, < 8.1:2021-07-01≥ 9:0, < 9:2021-07-012021-07-01
CVE-2021-0588 CVE-2021-0588: In processInboundMessage of MceStateMachine
In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0549UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0549 CVE-2021-0549: In sspRequestCallback of BondStateMachine
In sspRequestCallback of BondStateMachine.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0328UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0328 CVE-2021-0328: In onBatchScanReports and deliverBatchScan of GattService
In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0329UNKNOWN≥ 8.0:0, < 8.0:2021-02-01≥ 8.1:0, < 8.1:2021-02-01+3 more2021-02-01
CVE-2021-0329 CVE-2021-0329: In several native functions called by AdvertiseManager
In several native functions called by AdvertiseManager.java, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the Bluetooth server with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-12856UNKNOWN≥ 11-next:0, < 11-next:2020-11-01≥ 8.0:0, < 8.0:2020-11-01+4 more2020-11-01
CVE-2020-12856 CVE-2020-12856: In smp_decide_association_model of smp_act
In smp_decide_association_model of smp_act.cc, there is a possible silent bluetooth pairing due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0410UNKNOWN≥ 8.0:0, < 8.0:2020-10-01≥ 8.1:0, < 8.1:2020-10-01+3 more2020-10-01
CVE-2020-0410 CVE-2020-0410: In setNotification of SapServer
In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv