CVE-2022-26468: Medium severity android vulnerability
In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07168125; Issue ID: ALPS07168125.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-26468.
What is the severity of CVE-2022-26468?
The severity of CVE-2022-26468 is medium, with a CVSS score of 6.6.
What is the affected software?
The affected software includes Google Android versions 11.0 and 12.0.
How can an attacker exploit CVE-2022-26468?
An attacker with physical access to the device can exploit CVE-2022-26468 through local escalation of privilege, with no additional execution privileges needed. User interaction is required for exploitation.
Is the Mediatek Mt6735 affected by CVE-2022-26468?
No, the Mediatek Mt6735 is not vulnerable to CVE-2022-26468.