PT-2022-14495 · Google · Android

Published

2022-08-11

·

Updated

2022-08-16

·

CVE-2022-20271

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description The issue is related to the PermissionController, where there is a possible way to grant some permissions without user consent due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
Recommendations For Android version Android-13, consider restricting access to the PermissionController until a fix is available. As a temporary workaround, ensure that users are cautious when interacting with permission requests to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2022-20271

Affected Products

Android