CVE Vulnerabilities

CVE-2026-0097

Protection Mechanism Failure

Published: Jun 01, 2026 | Modified: Jun 03, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle14.0 (including)14.0 (including)
AndroidGoogle15.0 (including)15.0 (including)
AndroidGoogle16.0 (including)16.0 (including)
AndroidGoogle16.0-qpr2_beta_1 (including)16.0-qpr2_beta_1 (including)
AndroidGoogle16.0-qpr2_beta_2 (including)16.0-qpr2_beta_2 (including)
AndroidGoogle16.0-qpr2_beta_3 (including)16.0-qpr2_beta_3 (including)

References