First published: Mon Nov 07 2022(Updated: )
In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-240138318
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-20452 is classified as a high severity vulnerability due to its potential for method arbitrary code execution.
To fix CVE-2022-20452, ensure that you update your Android device to the latest security patch provided by Google.
CVE-2022-20452 affects devices running Android 13.0 and potentially earlier versions.
CVE-2022-20452 represents a local escalation of privilege attack that does not require user interaction.
CVE-2022-20452 impacts the BaseBundle.java component in the Android framework.