PT-2022-14251 · Google · Android

Published

2022-05-01

·

Updated

2023-10-03

·

CVE-2022-20004

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-10 through Android-12L
Description The issue is related to improper input validation in the checkSlicePermission function of SliceManagerService.java, allowing access to any slice URI. This could lead to local escalation of privilege without needing additional execution privileges. User interaction is not required for exploitation.
Recommendations For Android versions Android-10 through Android-12L, consider restricting access to the checkSlicePermission function of SliceManagerService.java until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

ASB-A-179699767
CVE-2022-20004

Affected Products

Android