Permissions, Privileges, and Access Controls in Chromecast - CVE-2022-20114

 

Permissions, Privileges, and Access Controls in Chromecast - CVE-2022-20114

Published: July 19, 2022


Vulnerability identifier: #VU65443
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20114
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due the an error in placeCall of TelecomManager.java that allows an application to keep itself running with foreground service importance. A local application can can bypass security restrictions and escalate privileges on the system.


Affected software

Chromecast

How to mitigate CVE-2022-20114

Install updates from vendor's website.

Chromecast - update to 10 2022-02-05

External References

Related Security Bulletins