CVE-2022-20429: High severity android vulnerability
Published Oct 11, 2022
·Updated
In CarSettings of app packages, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-220741473
Affected Software
4 affected components
Google Android=10.0
Google Android=11.0
Google Android=12.0
Google Android=12.1
Event History
Oct 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-20429?
CVE-2022-20429 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2022-20429?
To fix CVE-2022-20429, users should update their Android devices to the latest available version.
3
What devices are affected by CVE-2022-20429?
CVE-2022-20429 affects Android versions 10.0, 11.0, 12.0, and 12.1.
4
Can CVE-2022-20429 be exploited remotely?
No, CVE-2022-20429 requires local access to exploit the vulnerability.
5
What impact does CVE-2022-20429 have on Bluetooth settings?
CVE-2022-20429 may allow local escalation of privileges within Bluetooth settings.