Arbitrary code execution in Google Android - CVE-2022-20469

 

Arbitrary code execution in Google Android - CVE-2022-20469

Published: December 7, 2022 / Updated: December 7, 2022


Vulnerability identifier: #VU69989
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-20469
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to compromise the affected device.

The vulnerability exists due to insufficient validation of untrused input within the Bluetooth component. An attacker with physical proximity to device can pass specially crafted input to the system and execute arbitrary code.


Affected software

Google Android

How to mitigate CVE-2022-20469

Install updates from vendor's website.

Google Android - addressed in versions 10 2022-12-01, 11 2022-12-01, 12L 2022-12-01, 12 2022-12-01, 13 2022-12-01

External References

Related Security Bulletins