PT-2022-25053 · Google · Android

Sergey Toshin

·

Published

2022-10-07

·

Updated

2023-06-27

·

CVE-2022-39862

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to SMR Sep-2022 Release 1 Android version 3.3.03.66 in Android S(12)
Description The issue is related to improper authorization in the Dynamic Lockscreen, allowing unauthorized use of the javascript interface api.
Recommendations For Android versions prior to SMR Sep-2022 Release 1, update to a version that includes the SMR Sep-2022 Release 1 security patch. For Android version 3.3.03.66 in Android S(12), consider restricting access to the Dynamic Lockscreen until a patch is available.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-39862

Affected Products

Android