PT-2022-14646 · Google · Android

Published

2022-10-01

·

Updated

2022-10-13

·

CVE-2022-20419

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-12L through Android-13
Description In the setOptions method of ActivityRecord.java, a logic error allows loading any arbitrary Java code into the launcher process. This could lead to local escalation of privilege without needing additional execution privileges. User interaction is not required for exploitation.
Recommendations For Android versions Android-12L through Android-13, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

ASB-A-237290578
CVE-2022-20419

Affected Products

Android