CVE-2022-20127
published 2022-06-15CVE-2022-20127: In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.66%
93.1th percentile
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221862119
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | system_nfc | >= 10:0 < 10:2022-06-01 | 10:2022-06-01 |
| platform | system_nfc | >= 11:0 < 11:2022-06-01 | 11:2022-06-01 |
| platform | system_nfc | >= 12:0 < 12:2022-06-01 | 12:2022-06-01 |
| platform | system_nfc | >= 12L-next:0 < 12L-next:2022-06-01 | 12L-next:2022-06-01 |
| platform | system_nfc | >= 12L:0 < 12L:2022-06-01 | 12L:2022-06-01 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered via NFC Type 4 Tag (T4T) data callback — monitor for anomalous NFC interactions targeting the ce_t4t_data_cback function in ce_t4t.cc ↗
- →No user interaction required and no additional privileges needed — exploitation can occur silently via proximity-based NFC communication, making passive NFC traffic anomalies a detection signal ↗
- →Affected Android versions are 10, 11, 12, and 12L — prioritize detection and patching on unpatched devices running these OS versions ↗
- ·This is a CRITICAL-rated RCE with no user interaction required, exploitable purely over NFC proximity — no network-based IOCs exist; detection must rely on host-based crash/tombstone analysis or NFC traffic inspection ↗
- ·The double-free vulnerability resides in the NFC Card Emulation (CE) subsystem; crash dumps or tombstones referencing ce_t4t.cc or ce_t4t_data_cback on affected Android versions should be treated as high-priority indicators ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC
cisa_ics·2024-03-14
Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 14, 2024
Alert CodeICSA-24-074-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Missing Encryption of Sensitive Data, Incorrect Permission Assignment for Critical Resource, Expected Beha
Android
CVE-2022-20127: Android Security Bulletin 2022-06-01
CVE: CVE-2022-20127
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 10, 11, 12, 12L
References: A-221862119
vendor_android·2022-06-01·CVSS 9.8
CVE-2022-20127 [CRITICAL] CVE-2022-20127: Android Security Bulletin 2022-06-01
CVE: CVE-2022-20127
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 10, 11, 12, 12L
References: A-221862119
Android Security Bulletin 2022-06-01
CVE: CVE-2022-20127
Severity: CRITICAL
Type: RCE
Affected AOSP versions: 10, 11, 12, 12L
References: A-221862119
GHSA
GHSA-v2rr-ww6m-w47m: In ce_t4t_data_cback of ce_t4t
ghsa_unreviewed·2022-06-16
CVE-2022-20127 [CRITICAL] CWE-787 GHSA-v2rr-ww6m-w47m: In ce_t4t_data_cback of ce_t4t
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221862119
OSV
CVE-2022-20127: In ce_t4t_data_cback of ce_t4t
osv·2022-06-01
CVE-2022-20127 CVE-2022-20127: In ce_t4t_data_cback of ce_t4t
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
Checkpoint
13th June – Threat Intelligence Report
blogs_checkpoint·2022-06-13
CVE-2022-30190 13th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The Italian municipality of Palermo has been victim of a ransomware attack that caused a large-scale service outage affecting over a million people. The attack was claimed by the Vice Society ransomware group, which used the double extortion ransomware
Shields Health Care Group, Massachusetts-based medical services provider, h
Threat Intel
UAT-8616
threat_intel·CVSS 7.8
CVE-2026-20127 [HIGH] UAT-8616
# Threat Actor: UAT-8616
## Description
UAT-8616 is a highly sophisticated cyber threat actor attributed by Cisco Talos, with evidence of activity dating back to at least 2023. They have been observed exploiting CVE-2026-20127 in the wild and previously exploited CVE-2022-20775 by escalating to root user access through a software version downgrade. Their operations indicate a focus on targeting network edge devices to establish persistent footholds in high-value organizations, including Critical Infrastructure sectors.
2022-06-15
Published