HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-0045Published Modified CNA google_android

CVE-2026-0045: In bta_jv_rfcomm_connect of bta_jv_act

In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a privilege-escalation vulnerability in the Android Bluetooth stack, specifically in the RFCOMM connection handler (bta_jv_rfcomm_connect in bta_jv_act.cc). A logic error allows a local attacker to bypass the bonding check that normally enforces secure Bluetooth connections, without needing elevated privileges or user interaction. Successful exploitation gives the attacker full read, write, and execution control over the affected process. HarborGuard tracks this advisory and will make a patched-image rebuild available as soon as a fix version is published upstream.

HarborGuard Coverage

Detection

Detection for CVE-2026-0045 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all images in customer registries and CI/CD pipelines, including custom-built Android-based container images. Coverage applies regardless of whether the image was pulled from a public registry or built internally.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 7.8 (High) and applying per-environment compliance policy weighting to adjust priority based on each customer org's risk tolerance. Triage routing is available to direct findings to the appropriate team inbox within each customer environment.

Available
Patch

Because no fix version has been published for CVE-2026-0045, HarborGuard re-checks the upstream advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Google publishes a remediated release. For customers with auto-remediation enabled, the rebuild, regression run, and PR against affected workloads will be triggered without manual intervention once the upstream fix lands.

Pending upstream

Exploit Conditions

  • Network reachabilityNot required

    The attacker needs an existing shell or process on the host; no network access to the target is required.

  • AuthenticationRequired

    Any low-privilege local account is sufficient; no administrative or elevated credentials are needed.

  • Victim interactionNot required

    Exploitation completes without any action from another user on the system.

  • Attack complexityDetail

    The exploit is reliable and condition-free; no race conditions or special environmental factors must be met.

Blast Radius

  • The attacker reads any data accessible to the compromised Bluetooth service process, including paired device records and connection metadata.
  • The attacker writes to or modifies data within the process context, including Bluetooth pairing state and connection configurations.
  • The attacker gains code execution at the privilege level of the Bluetooth stack process, enabling further lateral movement on the device.
  • All three impact dimensions (confidentiality, integrity, availability) are rated High, meaning the attacker achieves full effective control over the affected component.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-0045 is active across customer environments, matching affected Android image layers as soon as the CVE was published. Because Google has not yet released a fix version, HarborGuard monitors the upstream advisory on every ingest cycle. When a patched release is published, a rebuilt image will become available immediately; for customers with auto-remediation enabled, HarborGuard will trigger a rebuild, run regression tests, and open a PR against affected workloads automatically. In the interim, customers can apply compensating controls through HarborGuard network policy enforcement: isolating containers that expose Bluetooth-adjacent interfaces, applying egress filtering to limit lateral movement from a compromised process, and gating any feature flags that enable RFCOMM-based Bluetooth profiles in non-essential workloads.

See how HarborGuard automates this
Affected packages
  • Google / Android
    16-qpr2 · 16 · 15 · 14
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H