PT-2022-14620 · Google · Android

Published

2022-10-01

·

Updated

2023-08-08

·

CVE-2022-20394

CVSS v3.1

5.0

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-10 through Android-12L
Description The issue is related to a missing permission check in the getInputMethodWindowVisibleHeight function of InputMethodManagerService.java. This could allow an app to determine when another app is showing an Input Method Editor (IME), potentially leading to local information disclosure. No additional execution privileges are needed, but user interaction is required for exploitation.
Recommendations For Android versions Android-10 through Android-12L, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

ASB-A-204906124
CVE-2022-20394

Affected Products

Android