Junglewise Threat Intelligence

CVE-2026-0045: Google Android bonding bypass in Bluetooth RFCOMM

CVE-2026-0045 · Severity: info · CVSS 7.8 · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Android operating system's Bluetooth component. This flaw could allow a malicious application or local attacker to bypass standard security pairing (bonding) requirements when establishing a connection. If exploited, an attacker could gain unauthorized access to device functions or elevated privileges without any interaction from the user.

Technical details

A logic error exists within the 'bta_jv_rfcomm_connect' function in 'bta_jv_act.cc' of the Android Bluetooth stack. This vulnerability allows an attacker to bypass the bonding requirement for a secure RFCOMM connection. The flaw is categorized as an Elevation of Privilege (EoP) vulnerability that requires no additional execution privileges and no user interaction. It affects Android versions 14, 15, and 16. Google has addressed this issue in the June 2026 Android Security Bulletin with security patch level 2026-06-05.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses this issue.

References

Related threats