Description
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.
In plain language
AI Worth attentionCVE-2017-0785 is a Bluetooth weakness on older Android phones where someone nearby can read some sensitive information without you doing anything—most small businesses should patch if their Android versions are old or not regularly updated.
CVE-2017-0785 is an unauthenticated nearby information disclosure in Android’s Bluetooth stack (CWE-200), allowing a nearby attacker with Bluetooth enabled to read confidential data without user interaction.
What to do now
- Check your Android devices’ current security patch level and whether they received the Android security bulletin dated 2017-09-01 (or later).
- If you run Android versions in the affected list (4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0), upgrade to a version that includes the fix from the 2017-09-01 bulletin.
- Reduce exposure immediately: keep Bluetooth turned off when not needed, and avoid using Bluetooth while in public/near unknown devices.
- Confirm operational coverage: ensure any company-managed Android phones (MDM/Mobile Device Management) receive security updates and are on policies that enforce them.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-0785 and every CVE in our database. Create a free account — no credit card required.
Create Free Account