CVE-2022-21768: High severity Google Android vulnerability
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784351; Issue ID: ALPS06784351.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-21768?
CVE-2022-21768 is a vulnerability in Bluetooth that allows for a possible out of bounds write, leading to local escalation of privilege without additional execution privileges needed.
What is the severity of CVE-2022-21768?
The severity of CVE-2022-21768 is rated as high with a severity value of 8.8.
Which software is affected by CVE-2022-21768?
Google Android versions 8.1, 9.0, 10.0, 11.0, and 12.0 are affected by CVE-2022-21768.
Is user interaction needed for exploitation of CVE-2022-21768?
No, user interaction is not needed for the exploitation of CVE-2022-21768.
How can I fix CVE-2022-21768?
To fix CVE-2022-21768, apply the patch with ID ALPS06784351 or refer to the provided source for security bulletins from Google and MediaTek.