Unapproved Data Access in Android Bluetooth Adapter Service
CVE-2025-0093

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-0093?

A vulnerability in the Android Bluetooth Adapter Service allows for potential unauthorized access to sensitive data. The issue arises from a missing permission check in the handleBondStateChanged function within AdapterService.java. This deficiency can lead to remote information disclosure; however, successful exploitation requires user interaction. To mitigate this risk, users should ensure that their Android devices are updated to the latest security patches.

Affected Version(s)

Android 15

Android 14

Android 13

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-0093 : Unapproved Data Access in Android Bluetooth Adapter Service