PT-2022-14693 · Google · Android

Published

2022-12-01

·

Updated

2022-12-15

·

CVE-2022-20475

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-11 through Android-13
Description The issue is related to a confused deputy in the ResetTargetTaskHelper.java test, which could allow the hijacking of any app that sets allowTaskReparenting to true. This could lead to local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android versions Android-11 through Android-13, consider restricting the use of allowTaskReparenting to minimize the risk of exploitation until a patch is available.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

ASB-A-240663194
CVE-2022-20475

Affected Products

Android