PT-2022-14440 · Google · Android
Published
2022-07-13
·
Updated
2022-07-21
·
CVE-2022-20216
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions prior to the fixed version
Description
The issue concerns the
android exported setting used for third-party app access permissions, where the default value of intent-filter is true. Specifically, com.sprd.firewall has its exported value set to true. This could potentially allow unauthorized access to certain features or data.Recommendations
For Android versions prior to the fixed version, consider restricting access to the
com.sprd.firewall component to minimize the risk of exploitation. As a temporary workaround, review and adjust the intent-filter settings to ensure that only necessary permissions are granted to third-party apps. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android