PT-2022-14527 · Google · Android

Published

2022-08-11

·

Updated

2023-08-08

·

CVE-2022-20301

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description The issue concerns a missing permission check in Android, allowing an attacker to determine if an account exists on the device. This could lead to local information disclosure, requiring User execution privileges. No user interaction is needed for exploitation.
Recommendations For Android version Android-13, consider restricting access to sensitive account information until a patch is available. As a temporary workaround, review and enforce strict permission checks to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-20301

Affected Products

Android