First published: Fri Jul 29 2022(Updated: )
Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Google Play Services Software Development Kit | <18.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-1799.
The title of this vulnerability is 'Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug ver…'.
CVE-2022-1799 has a severity rating of 9.8 (critical).
CVE-2022-1799 allows a debug version of Google Play services to be trusted by the SDK for non-GMS devices.
To fix CVE-2022-1799, upgrade the Google Play services SDK to a version beyond the 2022-05-03 release.