CVE-2014-7914: Google Android
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via crafted Bluetooth packets after the tapping of a crafted NFC tag.
Affected products
- Google Android: before 5.1 (fixed in 5.1)
Published 2020-02-21. Last modified 2026-06-17.