Impact
Android’s AdapterService contains a logic error that permits skipping the pairing process. The flaw allows an attacker to gain elevated privileges on the device without requiring user consent or additional execution rights. This represents an authentication bypass that can compromise confidentiality, integrity, and availability of device data and services.
Affected Systems
This specific version information is available from the CNA; however the flaw resides in the core AdapterService component, which is present across multiple Android releases.
Risk and Exploitability
The vulnerability can be exploited remotely and does not require any user interaction, making it highly actionable for an attacker with network access to the device. The CVSS score of 9.8 indicates a very high severity. The EPSS score of < 1% indicates a low probability of exploitation, and the issue is not listed in the CISA KEV catalog; nevertheless, the nature of the flaw—remote privilege escalation—suggests potential for high impact if an exploit becomes available. No public exploit is known at this time, but the absence of an official patch increases exposure risk.
OpenCVE Enrichment