PT-2022-16319 · Google · Google Play Services Sdk

Published

2022-08-12

·

Updated

2022-08-17

·

CVE-2022-2390

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Google Play Services SDK versions prior to 18.0.2
Description The issue arises from the incorrect setting of the mutability flag in PendingIntents passed to the Notification service in apps developed with the Google Play Services SDK. This bug affects many applications due to the widespread use of the Google Play services SDK. An attacker can exploit this to gain access to all non-exported providers and/or gain access to other providers the victim has permissions.
Recommendations For versions prior to 18.0.2, upgrade to version 18.0.2 of the Play Service SDK and rebuild and redeploy apps. As a temporary workaround, consider restricting access to non-exported providers and limiting permissions to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2022-2390
GHSA-CM6R-892J-JV2G

Affected Products

Google Play Services Sdk