CVE-2022-20224: High severity Google Android vulnerability
In ATSKIPREST of btahfclientat.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure in the Bluetooth stack with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220732646
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20224?
CVE-2022-20224 has a high severity rating due to the potential for remote information disclosure.
How do I fix CVE-2022-20224?
To fix CVE-2022-20224, ensure that you are running the latest security updates for Android versions 10.0, 11.0, 12.0, or 12.1.
What is the impact of CVE-2022-20224?
The impact of CVE-2022-20224 is that it enables remote information disclosure in the Bluetooth stack without requiring user interaction.
Which Android versions are affected by CVE-2022-20224?
CVE-2022-20224 affects Android versions 10.0, 11.0, 12.0, and 12.1.
Is user interaction needed for exploiting CVE-2022-20224?
No, user interaction is not needed to exploit CVE-2022-20224.