Description
Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local users to gain privileges by establishing a pairing that remains present during a session of the primary user, aka internal bug 27410683.
References (4)
Core 4
Core References
Patch x_refsource_confirm
https://android.googlesource.com/platform/system/bt/+/37c88107679d36c419572732b4af6e18bb2f7dce
Patch x_refsource_confirm
https://android.googlesource.com/platform/hardware/libhardware/+/8b3d5a64c3c8d010ad4517f652731f09107ae9c5
Vendor Advisory x_refsource_confirm
http://source.android.com/security/bulletin/2016-07-01.html
Scores
CVSS v3
7.5
EPSS
0.0025
EPSS Percentile
15.7%
Attack Vector
ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-20
CWE-362
Status
published
Products (6)
google/android
5.0
google/android
5.0.1
google/android
5.1
google/android
5.1.0
google/android
6.0
google/android
6.0.1
Published
Jul 11, 2016
Tracked Since
Feb 18, 2026