VDB
CVE-2021-1037
CVE-2021-1037
PUBLISHED
CVSS 5.300000190734863 MEDIUM
The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for it. This lets apps keep track of what devices are paired without requesting BLUETOOTH permissions.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-162951906
EPSS 0.32% · 24.7th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.32%
24.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Android | Android-10 Android-11 Android-12 Android-9 |
| android | 11.0, 12.0, 10.0 |
Timeline
- Jan 14, 2022 CVE Published
- Jan 15, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 10, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jun 25, 2022 EPSS Score
- Aug 18, 2022 EPSS Score
- Oct 11, 2022 EPSS Score
- Dec 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 21, 2023 EPSS Score
- May 13, 2023 EPSS Score