CVE-2022-20226: Input Validation
In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213644870
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20226?
The severity of CVE-2022-20226 is classified as a medium risk due to potential local escalation of privileges.
How do I fix CVE-2022-20226?
To fix CVE-2022-20226, ensure that your device is updated to the latest available Android version that addresses this vulnerability.
Who is affected by CVE-2022-20226?
CVE-2022-20226 affects users of Android 12 and Android 12L running vulnerable versions of the operating system.
What type of vulnerability is CVE-2022-20226?
CVE-2022-20226 is classified as a tapjacking vulnerability due to improper input validation.
What are the potential impacts of CVE-2022-20226?
The potential impacts of CVE-2022-20226 include unauthorized access to user privileges, allowing an attacker to execute malicious actions if user interaction occurs.