CVE Vulnerabilities

CVE-2022-20474

Published: Dec 13, 2022 | Modified: Apr 22, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-240138294

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle10.0 (including)10.0 (including)
AndroidGoogle11.0 (including)11.0 (including)
AndroidGoogle12.0 (including)12.0 (including)
AndroidGoogle12.1 (including)12.1 (including)
AndroidGoogle13.0 (including)13.0 (including)
Android-platform-frameworks-baseUbuntubionic*
Android-platform-frameworks-baseUbuntudevel*
Android-platform-frameworks-baseUbuntuesm-apps/bionic*
Android-platform-frameworks-baseUbuntuesm-apps/focal*
Android-platform-frameworks-baseUbuntuesm-apps/jammy*
Android-platform-frameworks-baseUbuntuesm-apps/noble*
Android-platform-frameworks-baseUbuntuesm-apps/xenial*
Android-platform-frameworks-baseUbuntufocal*
Android-platform-frameworks-baseUbuntujammy*
Android-platform-frameworks-baseUbuntukinetic*
Android-platform-frameworks-baseUbuntulunar*
Android-platform-frameworks-baseUbuntumantic*
Android-platform-frameworks-baseUbuntunoble*
Android-platform-frameworks-baseUbuntuoracular*
Android-platform-frameworks-baseUbuntutrusty*
Android-platform-frameworks-baseUbuntuxenial*

References