Lucene search

K
cvelistGoogle_androidCVELIST:CVE-2022-20470
HistoryDec 13, 2022 - 12:00 a.m.

CVE-2022-20470

2022-12-1300:00:00
google_android
www.cve.org
cve-2022-20470 android-10 android-11 android-12 android-12l android-13 input validation local escalation privilege

0.0004 Low

EPSS

Percentile

5.1%

In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-234013191

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Android",
    "versions": [
      {
        "version": "Android-10 Android-11 Android-12 Android-12L Android-13",
        "status": "affected"
      }
    ]
  }
]

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2022-20470