PT-2022-14710 · Google · Android

Published

2022-12-01

·

Updated

2025-04-22

·

CVE-2022-20497

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-12 through Android-13
Description The issue is related to an incorrect state transition in the updatePublicMode method of NotificationLockscreenUserManagerImpl.java. This could lead to local information disclosure with physical access required and an app that runs above the lockscreen, with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android versions Android-12 through Android-13, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

ASB-A-246301979
CVE-2022-20497

Affected Products

Android