CVE Vulnerabilities

CVE-2022-20448

Published: Nov 08, 2022 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-237540408

Affected Software

Name Vendor Start Version End Version
Android Google 10.0 (including) 10.0 (including)
Android Google 11.0 (including) 11.0 (including)
Android Google 12.0 (including) 12.0 (including)
Android Google 12.1 (including) 12.1 (including)
Android Google 13.0 (including) 13.0 (including)
Android-framework-23 Ubuntu bionic *
Android-framework-23 Ubuntu devel *
Android-framework-23 Ubuntu esm-apps/bionic *
Android-framework-23 Ubuntu esm-apps/focal *
Android-framework-23 Ubuntu esm-apps/jammy *
Android-framework-23 Ubuntu esm-apps/noble *
Android-framework-23 Ubuntu focal *
Android-framework-23 Ubuntu jammy *
Android-framework-23 Ubuntu kinetic *
Android-framework-23 Ubuntu lunar *
Android-framework-23 Ubuntu mantic *
Android-framework-23 Ubuntu noble *
Android-framework-23 Ubuntu oracular *
Android-framework-23 Ubuntu trusty *

References