PT-2022-14423 · Google · Android
Published
2022-06-15
·
Updated
2022-06-24
·
CVE-2022-20195
CVSS v3.1
5.0
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions Android-12L
Description
The issue is related to the keystore library, where unsafe deserialization could prevent access to system settings, leading to a local denial of service. This requires user execution privileges and user interaction for exploitation.
Recommendations
For Android version Android-12L, update to a version that includes a fix for the unsafe deserialization issue in the keystore library. As a temporary workaround, consider restricting access to the system settings to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android