Impact
The vulnerability originates from a logic error in the btm_sec_encrypt_change function within btm_sec.cc, enabling a potential downgrade attack that can be executed on Android devices. The flaw allows attackers to obtain data handled by the affected Bluetooth stack without requiring elevated privileges or user interaction, resulting in a breach of confidentiality.
Affected Systems
Android operating systems are impacted, specifically devices running versions before the security bulletin released on 2026‑09‑01. The exact versions are not detailed in the advisory, but any device that has not applied the latest patch from Google is potentially vulnerable.
Risk and Exploitability
Because user interaction is not necessary, the attack vector is remote over the network and the vulnerability is not listed in CISA's KEV catalog, indicating no publicly known exploits. The CVSS score of 4.3 signals moderate severity, but the EPSS score of <1% indicates a very low probability of exploitation. Thus the risk is moderate but the likelihood of successful exploitation is low, making prompt remediation advisable.
OpenCVE Enrichment