CVE-2026-0045
Bluetooth Bonding Bypass in Android BTA
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the bta_jv_rfcomm_connect function of the bta_jv_act.cc file. It involves a logic error that allows a possible bypass of bonding for a secure connection.
Bonding is a security process that establishes trust between devices. The logic error means that this process can be bypassed, potentially allowing unauthorized access.
How can this vulnerability impact me? :
This vulnerability could lead to a local escalation of privilege without requiring any additional execution privileges or user interaction.
An attacker with local access could exploit this flaw to gain higher privileges on the affected system.