Impact
A missing permission check (CWE-862) in the writeToParcel method of BleRssiRangingCapabilities.java allows a local application to read the Bluetooth MAC address without requiring additional privileges or user interaction. The flaw exposes a unique hardware identifier that can be used for tracking or profiling a device.
Affected Systems
Google Android devices that incorporate BleRssiRangingCapabilities.java are affected. No specific Android release is identified, so the vulnerability may exist in any build that contains the unpatched Bluetooth RSSI ranging implementation.
Risk and Exploitability
The CVSS score of 3.3 classifies the severity as low, and the EPSS score of less than 1% indicates a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can obtain the MAC address by invoking the affected method from a malicious application on the same device, with no user consent or elevated rights. While the impact is limited to information disclosure, the exposed identifier can be leveraged for device profiling or other privacy‑related attacks.
OpenCVE Enrichment