PT-2022-9144 · Google · Android

Published

2022-01-14

·

Updated

2023-08-08

·

CVE-2021-1037

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions 9 through 12
Description The issue concerns a broadcast sent by DevicePickerFragment when a new device is paired, lacking permission checks. This allows any app to register and listen for the broadcast, enabling them to track paired devices without requiring BLUETOOTH permissions.
Recommendations For Android versions 9 through 12, as a temporary workaround, consider restricting access to the DevicePickerFragment broadcast until a patch is available. Avoid using the broadcast to track paired devices in apps that do not require BLUETOOTH permissions. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-1037

Affected Products

Android