CVE-2022-20028: High severity Google Android vulnerability
Published Feb 7, 2022
·Updated
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06198663; Issue ID: ALPS06198663.
Affected Software
12 affected components
Google Android
Google Android=8.1
Google Android=9.0
Google Android=10.0
Google Android=11.0
Google Android=12.0
MediaTek Mt8167
MediaTek Mt8175
MediaTek Mt8183
MediaTek Mt8362a
MediaTek Mt8365
MediaTek Mt8385
Event History
Feb 7, 2022
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Feb 9, 2022
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-20028?
The severity of CVE-2022-20028 is classified as high due to the potential for local escalation of privilege.
2
How do I fix CVE-2022-20028?
To fix CVE-2022-20028, ensure that your Android device is updated to the latest security patch provided by Google.
3
Which Android versions are affected by CVE-2022-20028?
CVE-2022-20028 affects Android versions 8.1, 9.0, 10.0, 11.0, and 12.0.
4
Is user interaction required to exploit CVE-2022-20028?
No, user interaction is not needed for the exploitation of CVE-2022-20028.
5
What type of vulnerability is CVE-2022-20028?
CVE-2022-20028 is an out of bounds write vulnerability in Bluetooth.