Junglewise Threat Intelligence

CVE-2026-0097: Google Android privilege escalation via Bluetooth LE pairing bypass

CVE-2026-0097 · Severity: info · Published 2026-06-01

Technologies: Google Android. Vendors: Google.

Executive brief

A logic error in the Android operating system allows a nearby attacker to pair a Bluetooth Low Energy (LE) device without the user's knowledge or consent. This bypasses the standard security prompts that usually require a person to manually approve new connections. If exploited, an attacker could gain unauthorized access or elevated privileges on the mobile device, potentially compromising user data or device control.

Technical details

A logic error exists in multiple locations within the Android System component related to Bluetooth Low Energy (LE) pairing. An attacker within physical proximity (adjacent/proximal network) can exploit this to bypass mandatory user interaction during the pairing process. This vulnerability allows for an escalation of privilege (EoP) without requiring any prior execution privileges or user consent. The issue affects Android versions 14, 15, 16, and 16-qpr2. Google has addressed this in the June 2026 Android Security Bulletin with security patch level 2026-06-05 or later.

Affected products

  • Google Android 14, 15, 16, 16-qpr2

Timeline

  • 2026-06-01: disclosed: Vulnerability published in Android Security Bulletin and NVD.
  • 2026-06-05: patched: Security patch level 2026-06-05 or later addresses the issue.

References

Related threats