Android Audio Service Bluetooth MAC Address Information Disclosure Vulnerability

Vulnerability

A vulnerability in the Audio Service component of Android could allow unauthorized access to the MAC addresses of nearby Bluetooth devices. This issue arises from a lack of proper permission checks, potentially leading to a local elevation of privilege. Notably, exploitation of this vulnerability does not require any additional execution privileges or user interaction.

Impact

Exploitation of this vulnerability could result in unauthorized access to Bluetooth MAC addresses of nearby devices, potentially allowing for tracking or other privacy-invasive actions.

Remediation

Users can update their devices to Android 16 with a security patch level of 2025-07-01 or later to address this vulnerability.

Added: Sep 5, 2025, 5:33 PM
Updated: Sep 5, 2025, 6:03 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.7
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.