CVE-2022-20229: Critical severity Google Android vulnerability
In btahfclienthandlecindlistitem of btahfclientat.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-224536184
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20229?
CVE-2022-20229 is classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2022-20229?
To fix CVE-2022-20229, users should update their Android devices to the latest available software version.
Which Android versions are affected by CVE-2022-20229?
CVE-2022-20229 affects Android versions 10.0, 11.0, 12.0, and 12.1.
What kind of attack does CVE-2022-20229 facilitate?
CVE-2022-20229 facilitates remote code execution without user interaction due to a missing bounds check.
Is user interaction required to exploit CVE-2022-20229?
No, exploitation of CVE-2022-20229 does not require any user interaction.