In bluetooth driver, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.unisoc.com/en_us/secy/announcementDetail/1621031430231134210 | vendor advisory |