CVE-2021-0589

HIGH

Android -11,8.1,9,10 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2021-0589. PoCs published by Satheesh575555, Trinadh465.

AI-analyzed exploit summary This repository contains the Fluoride Bluetooth stack source code, including build instructions and documentation. It does not include exploit code but provides technical details about the Bluetooth stack implementation, which could aid in understanding CVE-2021-0589.

Description

In BTM_TryAllocateSCN of btm_scn.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-180939982

Exploits (2)

nomisec WRITEUP
by Satheesh575555 · poc
https://github.com/Satheesh575555/system_bt_AOSP10_r33_CVE-2021-0589

This repository contains the Fluoride Bluetooth stack source code, including build instructions and documentation. It does not include exploit code but provides technical details about the Bluetooth stack implementation, which could aid in understanding CVE-2021-0589.

Classification
Writeup 90%
Attack Type
Other
Complexity
Complex
Reliability
Theoretical
Target: Fluoride Bluetooth stack (AOSP10 r33)
No auth needed
Prerequisites: Access to the Bluetooth stack source code · Understanding of Bluetooth protocols
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WRITEUP
by Trinadh465 · poc
https://github.com/Trinadh465/System_bt_AOSP10_r33_CVE-2021-0589

This repository contains the Fluoride Bluetooth stack source code, which is the affected component for CVE-2021-0589. It includes build instructions, documentation, and source files but does not contain an explicit exploit or proof-of-concept code for the vulnerability.

Classification
Writeup 90%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Fluoride Bluetooth stack (AOSP)
No auth needed
Prerequisites: Access to the Bluetooth stack source code · Build environment setup
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0027
EPSS Percentile 17.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (4)
google/android 8.1
google/android 9.0
google/android 10.0
google/android 11.0
Published Jul 14, 2021
Tracked Since Feb 18, 2026