CVE-2025-0093: High severity Google Android vulnerability
In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0093?
CVE-2025-0093 is considered a moderate severity vulnerability due to its potential for remote information disclosure.
How do I fix CVE-2025-0093?
To mitigate CVE-2025-0093, ensure you update your affected Android devices to the latest security patch provided by Google.
Which versions of Android are affected by CVE-2025-0093?
CVE-2025-0093 affects Android versions 12.0, 12.1, 13.0, 14.0, and 15.0.
What impact does CVE-2025-0093 have on users?
CVE-2025-0093 could lead to unapproved data access and remote information disclosure requiring user interaction.
Is user interaction required to exploit CVE-2025-0093?
Yes, exploiting CVE-2025-0093 requires user interaction, which is necessary for the vulnerability to be leveraged.