First published: Mon Jul 11 2022(Updated: )
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =10.0 | |
Google Android | =11.0 | |
Google Android | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30753 has a high severity rating due to its potential to allow local attackers to access sensitive device information.
To fix CVE-2022-30753, ensure your device is updated to the latest security patch provided by Google for Android versions 10.0, 11.0, or 12.0.
Devices running Android versions 10.0, 11.0, and 12.0 are affected by CVE-2022-30753.
CVE-2022-30753 can be exploited by local attackers who can gain unauthorized access to a unique device ID.
Currently, the best workaround for CVE-2022-30753 is to apply the relevant security updates from Google.