First published: Thu Aug 11 2022(Updated: )
In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-166269532
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-20340 is classified as a medium severity vulnerability due to its potential for local information disclosure.
To mitigate CVE-2022-20340, users should update their Android devices to a version that includes the relevant security patches.
CVE-2022-20340 affects devices running Android version 13.0.
Exploitation of CVE-2022-20340 could lead to local information disclosure regarding which websites are accessed through the browser.
No, user interaction is not needed to exploit CVE-2022-20340.