CVE-2022-20056: Medium severity android vulnerability
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160820.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20056?
CVE-2022-20056 is a vulnerability in the preloader (usb) that allows for a possible out of bounds write, leading to local escalation of privilege.
Who is affected by CVE-2022-20056?
The vulnerability affects devices running Google Android versions 10.0, 11.0, and 12.0.
How can an attacker exploit CVE-2022-20056?
In order to exploit this vulnerability, an attacker would need physical access to the device and user interaction.
What is the severity of CVE-2022-20056?
CVE-2022-20056 has a medium severity rating, with a CVSS score of 6.6.
How can I protect my device from CVE-2022-20056?
To protect your device, it is recommended to apply the patch provided by the vendor as soon as it becomes available.