In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Android | 14.0 (including) | 14.0 (including) | |
| Android | 15.0 (including) | 15.0 (including) | |
| Android | 16.0 (including) | 16.0 (including) | |
| Android | 16.0-qpr2_beta_1 (including) | 16.0-qpr2_beta_1 (including) | |
| Android | 16.0-qpr2_beta_2 (including) | 16.0-qpr2_beta_2 (including) | |
| Android | 16.0-qpr2_beta_3 (including) | 16.0-qpr2_beta_3 (including) |