First published: Thu Aug 11 2022(Updated: )
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-194694094
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-20309 has been rated as a moderate severity vulnerability.
To address CVE-2022-20309, ensure your Android device is updated to the latest available version.
CVE-2022-20309 can lead to local information disclosure about whether specific applications are installed on the device.
No, user interaction is not required for the exploitation of CVE-2022-20309.
CVE-2022-20309 specifically affects Android version 13.0.