CVE-2022-20360: High severity android vulnerability
In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228314987
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20360?
CVE-2022-20360 is classified as a high severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2022-20360?
To mitigate CVE-2022-20360, you should ensure that permission checks are properly implemented in the application code.
Which versions of Android are affected by CVE-2022-20360?
CVE-2022-20360 affects Android versions 10.0, 11.0, 12.0, and 12.1.
What kind of attack does CVE-2022-20360 allow?
CVE-2022-20360 allows for local escalation of privilege without requiring additional execution privileges or user interaction.
Who can exploit CVE-2022-20360?
CVE-2022-20360 can be exploited by a guest user on the affected Android devices.