PT-2022-19705 · Google · Android Google Search App

Published

2022-12-13

·

Updated

2023-07-21

·

CVE-2022-29580

CVSS v3.1

8.9

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Android Google Search app versions prior to 13.41
Description The issue is caused by the incorrect usage of uri.getLastPathSegment, allowing a symbolic encoded string to bypass path logic and access unintended directories. This could lead to code execution on the device.
Recommendations For versions prior to 13.41, upgrade beyond version 13.41 to resolve the issue. As a temporary workaround, consider restricting access to sensitive directories until the update is applied.

Exploit

Fix

Path traversal

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2022-29580

Affected Products

Android Google Search App