PT-2022-14747 · Google · Android

Published

2022-12-16

·

Updated

2022-12-20

·

CVE-2022-20533

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description A missing permission check in the getSlice function of WifiSlice.java allows for a possible connection to a new WiFi network from guest mode. This could lead to local escalation of privilege without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android version Android-13, consider restricting access to the WifiSlice.java module to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the guest mode may help mitigate the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-20533

Affected Products

Android