PT-2022-14745 · Google · Android

Published

2022-12-16

·

Updated

2022-12-20

·

CVE-2022-20530

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description The issue is related to a possible permission bypass in strings.xml due to a misleading string, which could lead to remote information disclosure of call logs without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android version Android-13, update to a version that includes the fix for this issue, as indicated by Android ID: A-231585645.

Fix

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

CVE-2022-20530

Affected Products

Android