PT-2022-14572 · Google · Android

Published

2022-08-01

·

Updated

2025-10-20

·

CVE-2022-20347

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-10 through Android-12L
Description A permission bypass issue exists due to a confused deputy in the ConnectedDeviceDashboardFragment.java file. This could lead to remote escalation of privilege in Bluetooth settings without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android versions Android-10 through Android-12L, apply the fix provided by the Android security update to resolve the issue.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ASB-A-228450811
CVE-2022-20347

Affected Products

Android