CVE-2026-28606: Security vulnerability
Published Sep 8, 2026
·Updated
In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User interaction is not needed for exploitation.
Event History
Sep 8, 2026
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The issue is described as remotely exploitable and does not require additional execution privileges.
2
Does exploitation require the victim to take any action?
No user interaction is needed for exploitation, and the reported impact includes escalation of privilege without user consent.