First published: Thu Aug 11 2022(Updated: )
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-194694069
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-20318 is considered moderate due to local information disclosure risks.
To fix CVE-2022-20318, ensure that your device's Android version is updated to a version beyond 13.0 that addresses this vulnerability.
CVE-2022-20318 affects devices running Android version 13.0.
CVE-2022-20318 could be exploited by malicious applications through side channel information to determine installed apps.
No, user interaction is not needed for the exploitation of CVE-2022-20318.