PT-2019-16307 · Google · Android

Published

2019-12-06

·

Updated

2019-12-09

·

CVE-2019-2225

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions 8.0 through 10
Description A potential issue exists when pairing with a Bluetooth device, allowing a malicious device to pair without user confirmation. This paired device may interact with the phone, potentially leading to remote escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations For Android versions 8.0 through 10, consider disabling Bluetooth pairing until a fix is available to prevent potential exploitation. Restrict access to sensitive phone features to minimize the risk of privilege escalation.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-2225

Affected Products

Android