VDB

CVE-2021-1037

CVE-2021-1037 PUBLISHED CVSS 5.300000190734863 MEDIUM

The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for it. This lets apps keep track of what devices are paired without requesting BLUETOOTH permissions.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-162951906

EPSS 0.32% · 24.7th percentile

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.32%
24.7th percentile

Affected Products

VendorProductVersions
n/aAndroidAndroid-10 Android-11 Android-12 Android-9
googleandroid11.0, 12.0, 10.0

Timeline

  • Jan 14, 2022 CVE Published
  • Jan 15, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 10, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jun 25, 2022 EPSS Score
  • Aug 18, 2022 EPSS Score
  • Oct 11, 2022 EPSS Score
  • Dec 4, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 21, 2023 EPSS Score
  • May 13, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›