CVE-2022-20472: Critical severity android vulnerability
In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239210579
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-20472?
CVE-2022-20472 has a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2022-20472?
To fix CVE-2022-20472, update your Android device to the latest version provided by Google.
Which versions of Android are affected by CVE-2022-20472?
CVE-2022-20472 affects Android versions 10, 11, 12, 12.1, and 13.
Can CVE-2022-20472 be exploited without user interaction?
Yes, CVE-2022-20472 can be exploited remotely without any user interaction required.
What is the cause of CVE-2022-20472?
CVE-2022-20472 is caused by an out of bounds read due to an incorrect bounds check in LocaleListCache.cpp.