ASB-A-308429049 PUBLISHED

In multiple locations, there is a possible bypass of user consent to enabling new Bluetooth HIDs due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Products

VendorProductVersions
platformpackages/modules/Bluetooth13:0, 14, *
platformpackages/apps/Bluetooth*, 12:0, 12
platformsystem/bt12:0, *, *

Timeline

References

Open in Interactive Console →