First published: Thu Aug 11 2022(Updated: )
In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to local information disclosure of applications allow-listed to use the network during VPN lockdown mode with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-177239688
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-20336 is categorized as a moderate severity vulnerability resulting from a missing permission check.
To fix CVE-2022-20336, update your Android device to the latest security patch provided by Google.
CVE-2022-20336 can lead to local information disclosure of applications allowed to use the network during VPN lockdown mode.
CVE-2022-20336 specifically affects Google Android version 13.0.
No, user interaction is not needed to exploit CVE-2022-20336, making it potentially easier for attackers.