PT-2022-14695 · Google · Android

Published

2022-12-01

·

Updated

2022-12-15

·

CVE-2022-20477

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android version Android-13
Description A logic error in the code of KeyguardNotificationVisibilityProvider.kt allows hidden notifications to be shown, potentially leading to local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android version Android-13, update to a version that includes the fix for this issue to prevent potential exploitation. As a temporary workaround, consider restricting access to sensitive notifications until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

ASB-A-241611867
CVE-2022-20477

Affected Products

Android