Permissions, Privileges, and Access Controls in Google Android - CVE-2022-20438
Published: October 4, 2022
Vulnerability identifier: #VU67883
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-20438
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
No public exploit available
Affected software:
Google Android
SC9863A
SC9832E
SC7731E
T610
T310
T606
T760
T618
T612
T616
T770
T820
S8000
Google Android
SC9863A
SC9832E
SC7731E
T610
T310
T606
T760
T618
T612
T616
T770
T820
S8000
Detailed vulnerability description
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to unspecified error in UNISOC component. A local application can execute arbitrary code with elevated privileges.
How to mitigate CVE-2022-20438
Install updates from vendor's website.