First published: Fri Aug 12 2022(Updated: )
Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all non-exported providers and/or gain the access to other providers the victim has permissions. We recommend upgrading to version 18.0.2 of the Play Service SDK as well as rebuilding and redeploying apps.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Google Play Services Software Development Kit | <18.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2390 is a vulnerability in apps developed with Google Play Services SDK that incorrectly set the mutability flag to PendingIntents passed to the Notification service.
CVE-2022-2390 allows attackers to gain unauthorized access to applications that are affected.
The severity of CVE-2022-2390 is high.
Google Play Services SDK version 18.0.2 is affected by CVE-2022-2390.
To fix the CVE-2022-2390 vulnerability, developers should update to a version of Google Play Services SDK that is not affected.