CVE-2022-22267: Medium severity android vulnerability
Published Jan 7, 2022
·Updated
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
Affected Software
4 affected components
Google Android=9.0
Google Android=10.0
Google Android=11.0
Google Android=12.0
Event History
Jan 7, 2022
CVE Published
via MITRE·10:39 PM
Data Sourced
via MITRE·10:39 PM
DescriptionSeverityWeakness
Jan 10, 2022
Data Sourced
via NVD·02:12 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-22267?
CVE-2022-22267 is classified as a high severity vulnerability that allows attackers to obtain sensitive information about running applications.
2
How do I fix CVE-2022-22267?
To fix CVE-2022-22267, update your device to the latest Android version as per the manufacturer's security updates.
3
What software versions are affected by CVE-2022-22267?
CVE-2022-22267 affects Android versions 9.0, 10.0, 11.0, and 12.0.
4
What kind of attacks can exploit CVE-2022-22267?
CVE-2022-22267 can be exploited to hijack implicit intents, allowing unauthorized access to information about running applications.
5
Is CVE-2022-22267 being addressed by Android security updates?
Yes, CVE-2022-22267 has been addressed in the SMR (Security Maintenance Release) for January 2022 and subsequent updates.