PT-2022-14401 · Google · Android Kernel

Published

2022-06-15

·

Updated

2023-08-08

·

CVE-2022-20172

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to a missing permission check in the onbind method of ShannonRcsService.java. This could lead to local information disclosure without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android kernel, consider restricting access to sensitive data until a patch is available. As a temporary workaround, review and enforce proper permission checks in the onbind method of ShannonRcsService.java to prevent unauthorized access to protected data.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-20172

Affected Products

Android Kernel