In handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.