CVE-2022-20221: Input Validation
In avrcctrlparsvendorcmd of avrcparsct.cc, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205571133
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20221?
CVE-2022-20221 has a medium severity rating due to the potential for remote information disclosure.
How do I fix CVE-2022-20221?
To mitigate CVE-2022-20221, users should update their Android devices to the latest security patches provided by Google.
Which versions of Android are affected by CVE-2022-20221?
CVE-2022-20221 affects Android versions 10.0, 11.0, 12.0, and 12.1.
Is user interaction required to exploit CVE-2022-20221?
No, user interaction is not needed for the exploitation of CVE-2022-20221.
What type of vulnerability is CVE-2022-20221?
CVE-2022-20221 is an out-of-bounds read vulnerability due to improper input validation.