PT-2022-21829 · Google · Android Camera

Published

2022-07-11

·

Updated

2022-07-20

·

CVE-2022-33712

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android Camera versions prior to 12.0.01.64 Android Camera versions prior to 12.0.3.23 Android Camera versions prior to 12.0.0.98 Android Camera versions prior to 12.0.6.11 Android Camera versions prior to 12.0.3.19
However, to consolidate the ranges of affected versions into the most concise form and avoid redundant or overlapping statements, the above can be simplified to: Android Camera versions prior to 12.0.01.64, 12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19
Since all versions mentioned are prior to specific versions and there's no clear start and end version that encompasses all, we keep the list as is but acknowledge that the description implies all versions before these specified ones are affected. Thus, the most accurate and concise representation given the information is: Android Camera versions prior to 12.0.01.64, 12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19
Description The issue is related to an intent redirection vulnerability using implicit intent in the Camera application on Android S(12). This vulnerability allows an attacker to obtain sensitive information.
Recommendations For Android Camera version prior to 12.0.01.64, update to version 12.0.01.64 or later. For Android Camera version prior to 12.0.3.23, update to version 12.0.3.23 or later. For Android Camera version prior to 12.0.0.98, update to version 12.0.0.98 or later. For Android Camera version prior to 12.0.6.11, update to version 12.0.6.11 or later. For Android Camera version prior to 12.0.3.19, update to version 12.0.3.19 or later.
However, given the nature of the provided information, a more appropriate and concise recommendation would be: Update Android Camera to a version later than the highest version listed (e.g., 12.0.6.11 or later) to mitigate the risk.
But since the task requires specific guidance for each affected version and given that we cannot assume which of these versions is the "latest" without further context, the initial detailed recommendation is provided.
In practice, the best approach would be to update to the latest version available for your device, ensuring you are protected against this vulnerability.
At the moment, there is no information about a newer version that contains a fix for this vulnerability beyond the versions listed.

Fix

Improper Authorization

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-33712

Affected Products

Android Camera