PT-2022-19705 · Google · Android Google Search App
Published
2022-12-13
·
Updated
2023-07-21
·
CVE-2022-29580
CVSS v3.1
8.9
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Android Google Search app versions prior to 13.41
Description
The issue is caused by the incorrect usage of
uri.getLastPathSegment, allowing a symbolic encoded string to bypass path logic and access unintended directories. This could lead to code execution on the device.Recommendations
For versions prior to 13.41, upgrade beyond version 13.41 to resolve the issue. As a temporary workaround, consider restricting access to sensitive directories until the update is applied.
Exploit
Fix
Path traversal
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android Google Search App