CVE-2022-20392: Input Validation
In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to improper input validation. This could lead to local escalation of privilege during app installation or upgrade with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-213323615
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20392?
CVE-2022-20392 is considered a high severity vulnerability due to the potential for local escalation of privileges.
What versions of Android are affected by CVE-2022-20392?
CVE-2022-20392 affects Android versions 10.0, 11.0, 12.0, and 12.1.
How do I fix CVE-2022-20392?
To fix CVE-2022-20392, ensure that your Android device is updated to the latest security patches provided by Google.
What is the impact of CVE-2022-20392?
The impact of CVE-2022-20392 is the potential for dangerous permission access without user consent, allowing local privilege escalation.
Is CVE-2022-20392 related to app installation?
Yes, CVE-2022-20392 can lead to privilege escalation during app installation or upgrades due to improper input validation.