Executive brief
A vulnerability in the Android operating system's Bluetooth service could allow a malicious local application to access sensitive information without proper authorization. This occurs during the process of pairing or bonding devices. An attacker could exploit this to bypass security permissions and view data they should not have access to, potentially compromising user privacy.
Technical details
A permissions bypass vulnerability exists in the 'handleBondStateChanged' method within 'AdapterService.java' of the Android System component. The flaw allows a local attacker to bypass permission checks during Bluetooth bonding state changes. Successful exploitation enables the disclosure of sensitive information to a local process without requiring additional execution privileges or user interaction. The issue is addressed in the June 2026 Android Security Bulletin for AOSP versions 15 and 16.
Affected products
- Google Android 15, 16, 16-qpr2
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory
- 2026-06-01: patched