CVE-2022-38697: Medium severity android vulnerability
In messaging service, there is a missing permission check. This could lead to access unexpected provider in contacts service with no additional execution privileges needed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38697?
The severity of CVE-2022-38697 is categorized as medium due to the potential for unauthorized access to contact information.
How does CVE-2022-38697 affect Android devices?
CVE-2022-38697 affects Android devices running versions 10.0, 11.0, and 12.0, due to a missing permission check in the messaging service.
How do I fix CVE-2022-38697?
To fix CVE-2022-38697, ensure that your Android device is updated to the latest version provided by your manufacturer.
Can CVE-2022-38697 allow access to sensitive contacts?
Yes, CVE-2022-38697 can potentially allow unauthorized access to sensitive contacts stored on the device.
Are all Unisoc devices vulnerable to CVE-2022-38697?
No, Unisoc devices like S8000, SC7731, and others do not exhibit vulnerability to CVE-2022-38697.