First published: Tue May 09 2023(Updated: )
In phoneEx service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
Credit: security@unisoc.com security@unisoc.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Google Android | =10.0 | |
Any of | ||
Unisoc S8000 | ||
Unisoc SC7731E | ||
Unisoc SC9832E | ||
Unisoc SC9863A | ||
Unisoc T310 | ||
Unisoc T606 | ||
Unisoc T610 | ||
Unisoc T612 | ||
Unisoc T616 | ||
UniSoc T618 | ||
Unisoc T760 | ||
Unisoc T770 | ||
Unisoc T820 | ||
Google Android | =10.0 | |
Unisoc S8000 | ||
Unisoc SC7731E | ||
Unisoc SC9832E | ||
Unisoc SC9863A | ||
Unisoc T310 | ||
Unisoc T606 | ||
Unisoc T610 | ||
Unisoc T612 | ||
Unisoc T616 | ||
UniSoc T618 | ||
Unisoc T760 | ||
Unisoc T770 | ||
Unisoc T820 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-44433 is considered to have a moderate severity due to the potential for local escalation of privilege.
To mitigate CVE-2022-44433, ensure that proper permission checks are implemented in the phoneEx service.
CVE-2022-44433 affects devices running Google Android 10.0.
CVE-2022-44433 cannot be exploited remotely as it requires local access to the affected device.
Users of devices with Google Android 10.0 and the specific phoneEx service are at risk from CVE-2022-44433.