First published: Fri Dec 16 2022(Updated: )
In HalCoreCallback of halcore.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure from the NFC firmware with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-229994861
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | =13.0 | |
=13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-20527 is classified as moderate due to the potential for local information disclosure.
To fix CVE-2022-20527, users should update their Android device to the latest version that addresses this vulnerability.
CVE-2022-20527 affects users running Android version 13.0.
CVE-2022-20527 enables a possible local information disclosure attack due to a missing bounds check.
No, user interaction is not needed for exploiting CVE-2022-20527.