Android Bluetooth Module Cross-User Data Leak Vulnerability

Vulnerability

A logic error in the Bluetooth file transfer module can cause a cross-user data leak, allowing local information disclosure without requiring additional execution privileges or user interaction. This vulnerability affects the Android Bluetooth module, specifically in the 'isContentUriForOtherUser' function of 'BluetoothOppSendFileInfo.java'.

Impact

Exploitation of this vulnerability could lead to unauthorized access to user data from another profile.

Reproduction

The vulnerability can be reproduced by building and running the Android Open Source Project (AOSP) with the 'android-latest-release' branch. Once the Bluetooth module is active, the 'BluetoothOppSendFileInfo' class can be tested using the 'BluetoothOppSendFileInfoTest' unit test, which will trigger the cross-user data leak by accessing content URIs intended for other users.

Remediation

Users can update their devices to the June 2025 security patch level to address this vulnerability.

Added: Sep 4, 2025, 6:46 PM
Updated: Sep 4, 2025, 6:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.7
remediation
0.0
relevance
0.5
threat
4.8
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.