8.4
CWE
471
Advisory Published
Updated

CVE-2022-2390: Mutable pending intent in Google Play services SDK

First published: Fri Aug 12 2022(Updated: )

Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all non-exported providers and/or gain the access to other providers the victim has permissions. We recommend upgrading to version 18.0.2 of the Play Service SDK as well as rebuilding and redeploying apps.

Credit: cve-coordination@google.com

Affected SoftwareAffected VersionHow to fix
Google Google Play Services Software Development Kit<18.0.2

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2022-2390?

    CVE-2022-2390 is a vulnerability in apps developed with Google Play Services SDK that incorrectly set the mutability flag to PendingIntents passed to the Notification service.

  • How does CVE-2022-2390 affect applications?

    CVE-2022-2390 allows attackers to gain unauthorized access to applications that are affected.

  • What is the severity of CVE-2022-2390?

    The severity of CVE-2022-2390 is high.

  • Which version of Google Play Services SDK is affected by CVE-2022-2390?

    Google Play Services SDK version 18.0.2 is affected by CVE-2022-2390.

  • How can I fix the CVE-2022-2390 vulnerability?

    To fix the CVE-2022-2390 vulnerability, developers should update to a version of Google Play Services SDK that is not affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203