CVE-2022-20225: Medium severity Google Android vulnerability
In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-213457638
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Who is exposed to this issue?
Devices running Android 10, Android 11, Android 12, or Android 12L are listed as affected. Exploitation is local, so the attacker must already be able to run with local access on the device.
What access does an attacker need?
The CVSS vector indicates low privileges are required and no user interaction is needed. The issue can disclose a sensitive identifier without requiring additional execution privileges.
What is the impact of successful exploitation?
Successful exploitation can result in disclosure of a sensitive identifier. The provided CVSS vector indicates confidentiality impact only, with no integrity or availability impact.
What should be done to remediate the issue?
Apply the available patch for the affected Android version. The issue is tracked as Android ID A-213457638.