CVE-2024-0028
BaseFortify
Publication date: 2025-09-05
Last updated on: 2025-09-08
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| android | 16.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Audio Service where a missing permission check allows an attacker to obtain the MAC addresses of nearby Bluetooth devices. Exploiting this does not require user interaction or additional execution privileges, potentially enabling local escalation of privilege.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing an attacker with local access to escalate their privileges without needing extra execution rights or user interaction. They could obtain MAC addresses of nearby Bluetooth devices, which may be used for tracking or further attacks.