CVE-2026-0050
Bluetooth AdapterService Permissions Bypass Information Disclosure
Publication date: 2026-06-01
Last updated on: 2026-06-02
Assigner: Android (associated with Google Inc. or Open Handset Alliance)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the handleBondStateChanged method of the AdapterService.java file. It involves a permissions bypass that can lead to the disclosure of sensitive information locally. Exploiting this vulnerability does not require any additional execution privileges or user interaction.
How can this vulnerability impact me? :
The impact of this vulnerability is the potential local disclosure of sensitive information. Since no additional privileges or user interaction are needed, an attacker with local access could exploit this flaw to access information that should be protected.