ASB-A-195410559
Dashboard / Vulnerabilities / ASB-A-195410559
Summary:
Details: In bta_dm_remove_device of bta_dm_act.cc, there is a possible way for a BT device to receive a long term trackable identifier due to a permissions bypass. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References: https://source.android.com/security/bulletin/2022-10-01, https://android.googlesource.com/platform/packages/modules/Bluetooth/+/8f848255dea47710275f1eac7c4e635b1f5faa0b, https://android.googlesource.com/platform/packages/modules/Bluetooth/+/90d2a6a82b35e32f70938112125a202a7f37964b
Affected packages
Package
Name: platform/packages/modules/Bluetooth
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 13:0
Fixed -13:2022-10-01
Affected versions
13
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
