CVE-2022-20220: Path Traversal
Published Jul 6, 2022
·Updated
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-219015884
Affected Software
3 affected components
Google Android=12.0
Google Android=12.1
Google Android
Remediation
Patch Available
Event History
Jul 6, 2022
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Jul 13, 2022
CVE Published
via MITRE·06:22 PM
Data Sourced
via MITRE·06:22 PM
DescriptionWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
An attacker needs local access and User-level execution privileges on an affected device. No user interaction is required.
2
Which Android versions are identified as affected?
The issue affects Android 12 and Android 12L. The available CVSS vector indicates local attack access rather than remote exploitation.
3
What is the recommended remediation?
A patch is available. Apply the relevant Android security update from the device manufacturer or platform provider.