CVE-2022-20223: High severity Google Android vulnerability
In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-223578534
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20223?
CVE-2022-20223 is classified as a high severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2022-20223?
To fix CVE-2022-20223, update your Android device to the latest available version that addresses this vulnerability.
What versions of Android are affected by CVE-2022-20223?
CVE-2022-20223 affects Android versions 10.0, 11.0, 12.0, and 12.1.
Can CVE-2022-20223 be exploited without user interaction?
Yes, CVE-2022-20223 can be exploited without any user interaction required.
What impact does CVE-2022-20223 have on Android users?
CVE-2022-20223 may allow unauthorized phone calls to be initiated, leading to a potential breach of privacy.