PT-2022-14556 · Google · Android

Published

2022-08-11

·

Updated

2023-08-08

·

CVE-2022-20330

CVSS v3.1

3.5

Low

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description The issue is related to a missing permission check in Bluetooth, allowing devices to be connected or disconnected without user awareness. This could lead to local escalation of privilege, with user execution privileges needed. No user interaction is required for exploitation.
Recommendations For Android version Android-13, consider restricting Bluetooth device connections to trusted devices until a patch is available. As a temporary workaround, consider disabling Bluetooth functionality until a fix is provided. Restrict access to Bluetooth settings to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-20330

Affected Products

Android