CVE-2022-22270: Code Injection
Published Jan 7, 2022
·Updated
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.
Affected Software
3 affected components
Google Android=9.0
Google Android=10.0
Google Android=11.0
Event History
Jan 7, 2022
CVE Published
via MITRE·10:39 PM
Data Sourced
via MITRE·10:39 PM
DescriptionSeverityWeakness
Jan 10, 2022
Data Sourced
via NVD·02:12 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-22270?
CVE-2022-22270 has been classified with a moderate severity level due to the potential for unauthorized access to contact information.
2
How do I fix CVE-2022-22270?
To fix CVE-2022-22270, update your Android device to the latest security patch provided by your manufacturer.
3
Which versions of Android are affected by CVE-2022-22270?
CVE-2022-22270 affects Android versions 9.0, 10.0, and 11.0.
4
What type of vulnerability is CVE-2022-22270?
CVE-2022-22270 is an implicit Intent hijacking vulnerability that allows unprivileged applications to access sensitive contact information.
5
Who should be concerned about CVE-2022-22270?
Developers of applications on Android devices should be concerned about CVE-2022-22270 due to its potential impact on user privacy.