First published: Fri Jan 07 2022(Updated: )
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
Credit: mobile.security@samsung.com mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =9.0 | |
Google Android | =10.0 | |
Google Android | =11.0 | |
=9.0 | ||
=10.0 | ||
=11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22266 is rated as a moderate severity vulnerability affecting specific models in the TencentWifiSecurity application.
To mitigate CVE-2022-22266, update the TencentWifiSecurity application to the latest version provided in the SMR Jan-2022 Release 1.
CVE-2022-22266 affects Google Android versions 9.0, 10.0, and 11.0 on applicable China models.
CVE-2022-22266 is an unprotected service vulnerability that allows unauthorized access to WiFi information.
Yes, untrusted applications can exploit CVE-2022-22266 to access WiFi information without proper permissions.