PT-2022-14357 · Google · Android
Published
2022-05-01
·
Updated
2022-05-16
·
CVE-2022-20113
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions Android-12 through Android-12L
Description
A logic error in the DefaultUsbConfigurationPreferenceController.java could allow for the enablement of file transfer mode, potentially leading to local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations
For Android versions Android-12 through Android-12L, consider restricting the use of the
DefaultUsbConfigurationPreferenceController until a patch is available. As a temporary workaround, avoid using the file transfer mode to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android