CVE-2017-0601

MEDIUM

Android 7.0-7.1.2 - Elevation of Privilege via Bluetooth File Acceptance

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-0601. PoCs published by heeeeen.

AI-analyzed exploit summary This PoC exploits CVE-2017-0601, a vulnerability in Android's Bluetooth component where an attacker can bypass user confirmation for incoming files by sending a broadcast intent to manipulate the file acceptance status. The code iterates through possible URIs to guess and accept incoming Bluetooth shares without user interaction.

Description

An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via bluetooth without user permission. This issue is rated as Moderate due to local bypass of user interaction requirements. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-35258579.

Exploits (1)

github WORKING POC 5 stars
by heeeeen · javapoc
https://github.com/heeeeen/CVE-PoC/tree/master/CVE-2017-0601

This PoC exploits CVE-2017-0601, a vulnerability in Android's Bluetooth component where an attacker can bypass user confirmation for incoming files by sending a broadcast intent to manipulate the file acceptance status. The code iterates through possible URIs to guess and accept incoming Bluetooth shares without user interaction.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Android Bluetooth (com.android.bluetooth)
No auth needed
Prerequisites: Physical proximity or Bluetooth connectivity to the target device · Target device must have Bluetooth enabled and be discoverable
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_confirm
https://source.android.com/security/bulletin/2017-05-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/98137

Scores

CVSS v3 5.5
EPSS 0.0036
EPSS Percentile 27.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-732
Status published
Products (7)
google/android 7.0
google/android 7.1.0
google/android 7.1.1
google/android 7.1.2
Google Inc./Android 7.0
Google Inc./Android 7.1.1
Google Inc./Android 7.1.2
Published May 12, 2017
Tracked Since Feb 18, 2026