PT-2022-25107 · Google · Persona Manager
Sergey Toshin
·
Published
2022-12-08
·
Updated
2022-12-12
·
CVE-2022-39913
CVSS v3.1
6.8
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Persona Manager versions prior to Android T(13)
Description
The issue allows a local attacker to access user profiles information due to exposure of sensitive information to an unauthorized actor.
Recommendations
For versions prior to Android T(13), update to Android T(13) or later to resolve the issue.
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Persona Manager