CVE-2019-2197 is a local information disclosure vulnerability affecting Android versions 8.0 through 10, stemming from an insecure default value in the processPhonebookAccess function of CachedBluetoothDevice.java. This flaw allows an attacker to access a user's contact list without needing additional execution privileges, though user interaction is required for exploitation. The vulnerability is rated Medium severity with a CVSS score of 5.5, indicating a low attack complexity and requiring local access to the device. The primary impact is a high confidentiality breach, as it exposes sensitive user contact information. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered minimal community attention and media coverage, with no mentions across social media or news articles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0CPE matchmatch criteria | cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:google:android:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.