PT-2022-14444 · Google · Android

Published

2022-07-01

·

Updated

2022-07-25

·

CVE-2022-20220

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-12 through Android-12L
Description The issue is related to a possible permission bypass due to a path traversal error in the openFile function of CallLogProvider.java. This could lead to local escalation of privilege, requiring User execution privileges. No user interaction is needed for exploitation.
Recommendations For Android versions Android-12 through Android-12L, consider restricting access to the openFile function of CallLogProvider.java to minimize the risk of exploitation. As a temporary workaround, limiting the use of this function may help until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-219015884
CVE-2022-20220

Affected Products

Android