CVE-2022-20027: High severity Google Android vulnerability
Published Feb 7, 2022
·Updated
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126826; Issue ID: ALPS06126826.
Affected Software
12 affected components
Google Android
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android=11.0
Google Android=12.0
MediaTek Mt8167
MediaTek Mt8175
MediaTek Mt8183
MediaTek Mt8362a
MediaTek Mt8365
MediaTek Mt8385
Event History
Feb 7, 2022
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Feb 9, 2022
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-20027?
CVE-2022-20027 has been classified as a local escalation of privilege vulnerability.
2
How do I fix CVE-2022-20027?
To fix CVE-2022-20027, users should update their Google Android devices to the latest available security patch.
3
Which versions of Android are affected by CVE-2022-20027?
CVE-2022-20027 affects Google Android versions 8.1, 9.0, 10.0, 11.0, and 12.0.
4
Is user interaction needed to exploit CVE-2022-20027?
No, user interaction is not needed for the exploitation of CVE-2022-20027.
5
What kind of vulnerability is CVE-2022-20027?
CVE-2022-20027 is an out of bounds write vulnerability in the Bluetooth functionality of Android.