First published: Fri Jan 07 2022(Updated: )
A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows attackers to execute privileged action by hijacking and modifying the intent.
Credit: mobile.security@samsung.com mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung Bixby Routines | <3.1.21.8 | |
Google Android | =11.0 | |
Samsung Bixby Routines | <2.6.30.5 | |
Google Android | =10.0 | |
All of | ||
Samsung Bixby Routines | <3.1.21.8 | |
Google Android | =11.0 | |
All of | ||
Samsung Bixby Routines | <2.6.30.5 | |
Google Android | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22286 is classified as a high severity vulnerability due to its potential to allow unauthorized privileged actions.
To fix CVE-2022-22286, update Samsung Bixby Routines to version 3.1.21.8 or later.
CVE-2022-22286 affects Bixby Routines versions prior to 3.1.21.8.
CVE-2022-22286 affects devices running Android 10 (2.6.30.5 and below) and Android 11 (3.1.21.8 and below) with Bixby Routines installed.
CVE-2022-22286 allows attackers to hijack and modify intents, potentially executing privileged actions on the device.