CVE-2022-20230: Input Validation
In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221859869
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
Which devices are exposed?
Devices running Android 10, 11, 12, or 12L are identified as affected. Exploitation is local, so a remote attacker cannot trigger it solely over the network.
What does an attacker need to exploit this issue?
An attacker does not need additional execution privileges, but exploitation requires user interaction. The impact is disclosure of the user's certificate.
What should be done to remediate the issue?
A patch is available. Apply the relevant Android security update from the device vendor or platform update channel.