PT-2022-21829 · Google · Android Camera
Published
2022-07-11
·
Updated
2022-07-20
·
CVE-2022-33712
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android Camera versions prior to 12.0.01.64
Android Camera versions prior to 12.0.3.23
Android Camera versions prior to 12.0.0.98
Android Camera versions prior to 12.0.6.11
Android Camera versions prior to 12.0.3.19
However, to consolidate the ranges of affected versions into the most concise form and avoid redundant or overlapping statements, the above can be simplified to:
Android Camera versions prior to 12.0.01.64, 12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19
Since all versions mentioned are prior to specific versions and there's no clear start and end version that encompasses all, we keep the list as is but acknowledge that the description implies all versions before these specified ones are affected. Thus, the most accurate and concise representation given the information is:
Android Camera versions prior to 12.0.01.64, 12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19
Description
The issue is related to an intent redirection vulnerability using implicit intent in the Camera application on Android S(12). This vulnerability allows an attacker to obtain sensitive information.
Recommendations
For Android Camera version prior to 12.0.01.64, update to version 12.0.01.64 or later.
For Android Camera version prior to 12.0.3.23, update to version 12.0.3.23 or later.
For Android Camera version prior to 12.0.0.98, update to version 12.0.0.98 or later.
For Android Camera version prior to 12.0.6.11, update to version 12.0.6.11 or later.
For Android Camera version prior to 12.0.3.19, update to version 12.0.3.19 or later.
However, given the nature of the provided information, a more appropriate and concise recommendation would be:
Update Android Camera to a version later than the highest version listed (e.g., 12.0.6.11 or later) to mitigate the risk.
But since the task requires specific guidance for each affected version and given that we cannot assume which of these versions is the "latest" without further context, the initial detailed recommendation is provided.
In practice, the best approach would be to update to the latest version available for your device, ensuring you are protected against this vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability beyond the versions listed.
Fix
Improper Authorization
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android Camera