CVE-2022-20072 β€” Incorrect Comparison in Google Android

Severity
6.7MEDIUMNVD
EPSS
0.0%
top 89.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 11
Latest updateApr 12

Description

In search engine service, there is a possible way to change the default search engine due to an incorrect comparison. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no needed for exploitation. Patch ID: ALPS06219118; Issue ID: ALPS06219118.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages1 packages

β–ΆNVDgoogle/android11.0, 12.0+1

πŸ”΄Vulnerability Details

1
GHSA
GHSA-hxvv-256m-97hw: In search engine service, there is a possible way to change the default search engine due to an incorrect comparison↗2022-04-12
β–Ά
CVE-2022-20072 β€” Incorrect Comparison in Google Android | cvebase