PT-2022-14489 · Google · Android

Published

2022-08-11

·

Updated

2022-08-13

·

CVE-2022-20266

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Android versions prior to the fixed version
Description The issue is related to improper input validation in the Companion service, allowing it to run with elevated importance without displaying a foreground service notification. This could lead to local escalation of privilege, requiring user interaction for exploitation.
Recommendations For Android versions prior to the fixed version, consider restricting the use of the Companion service until a patch is available. As a temporary workaround, avoid using the service in a way that could lead to elevated importance without proper notification. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-20266

Affected Products

Android