Android Bluetooth HIDs User Consent Bypass Vulnerability Allowing Privilege Escalation
Vulnerability
A vulnerability exists in the Android Bluetooth module that allows for a bypass of user consent when enabling new Bluetooth Human Interface Devices (HIDs). This issue arises from a logic error in the code, which could lead to local escalation of privilege. Notably, exploitation of this vulnerability does not require any additional execution privileges or user interaction.
Impact
Exploitation of this vulnerability could result in unauthorized elevation of privileges, allowing a user to gain access to restricted functions or resources.
Remediation
Users can update their devices to the January 2025 security patch level to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
