PT-2023-15136 · Timmystudios · Timmystudios Fast Typing Keyboard

Published

2023-04-14

·

Updated

2025-02-07

·

CVE-2022-47027

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Timmystudios Fast Typing Keyboard version 1.275.1.162
Description The issue allows unauthorized apps to overwrite arbitrary files in the internal storage of Timmystudios Fast Typing Keyboard via a dictionary traversal vulnerability, which can lead to arbitrary code execution.
Recommendations For version 1.275.1.162, consider restricting access to the internal storage to prevent unauthorized overwrites until a patch is available. As a temporary workaround, avoid using the keyboard's internal storage for sensitive data until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-47027

Affected Products

Timmystudios Fast Typing Keyboard