CVE-2022-20358: High severity android vulnerability
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content providers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-203229608
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-20358?
CVE-2022-20358 is a vulnerability in the AbstractThreadedSyncAdapter.java file of Google Android, which could allow an attacker to access protected content of content providers without proper permission checks.
How severe is CVE-2022-20358?
CVE-2022-20358 has a severity rating of 3.3, indicating a high severity.
Which versions of Google Android are affected by CVE-2022-20358?
CVE-2022-20358 affects Google Android versions 10.0, 11.0, 12.0, and 12.1.
Can CVE-2022-20358 be exploited without user interaction?
No, exploitation of CVE-2022-20358 requires user execution privileges.
How can I mitigate or fix CVE-2022-20358?
To mitigate CVE-2022-20358, update to the latest version of Google Android and apply any available patches or security updates.