PT-2022-14618 · Google · Android

Published

2022-09-01

·

Updated

2022-09-17

·

CVE-2022-20392

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-10 through Android-12L
Description The issue is related to improper input validation in the declareDuplicatePermission function of ParsedPermissionUtils.java. This could allow an attacker to obtain a dangerous permission without user consent, potentially leading to local escalation of privilege during app installation or upgrade. No additional execution privileges are needed, and user interaction is not required for exploitation.
Recommendations For Android versions Android-10 through Android-12L, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

ASB-A-213323615
CVE-2022-20392

Affected Products

Android