Logic Error Causing Privilege Escalation in Android Bluetooth Networking
CVE-2026-0045

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-0045?

A logic error in the bta_jv_rfcomm_connect function within bta_jv_act.cc of Android's Bluetooth networking component allows for an unintended bypass of the bonding process required for establishing secure connections. This vulnerability facilitates local escalation of privilege, meaning an attacker can gain elevated access without the need for additional execution privileges. Importantly, user interaction is not necessary for exploitation, posing a significant risk to affected devices.

Affected Version(s)

Android 16-qpr2

Android 16

Android 15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.