PT-2021-13396 · Google · Android

Published

2021-12-15

·

Updated

2021-12-17

·

CVE-2021-0991

CVSS v2.0

2.7

Low

VectorAV:A/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-12
Description The issue is related to a possible leak of Bluetooth MAC addresses due to log information disclosure in the OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android version Android-12, consider restricting access to the log information to minimize the risk of exploitation. As a temporary workaround, disabling the logging of Bluetooth MAC addresses in the OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java may help until a patch is available.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-0991

Affected Products

Android