cbcvebase.
CVE-2022-20127
published 2022-06-15

CVE-2022-20127: In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.66%
93.1th percentile
In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221862119

Affected

11 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
googleandroid
platformsystem_nfc>= 10:0 < 10:2022-06-0110:2022-06-01
platformsystem_nfc>= 11:0 < 11:2022-06-0111:2022-06-01
platformsystem_nfc>= 12:0 < 12:2022-06-0112:2022-06-01
platformsystem_nfc>= 12L-next:0 < 12L-next:2022-06-0112L-next:2022-06-01
platformsystem_nfc>= 12L:0 < 12L:2022-06-0112L:2022-06-01

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via NFC Type 4 Tag (T4T) data callback — monitor for anomalous NFC interactions targeting the ce_t4t_data_cback function in ce_t4t.cc
  • No user interaction required and no additional privileges needed — exploitation can occur silently via proximity-based NFC communication, making passive NFC traffic anomalies a detection signal
  • Affected Android versions are 10, 11, 12, and 12L — prioritize detection and patching on unpatched devices running these OS versions
  • ·This is a CRITICAL-rated RCE with no user interaction required, exploitable purely over NFC proximity — no network-based IOCs exist; detection must rely on host-based crash/tombstone analysis or NFC traffic inspection
  • ·The double-free vulnerability resides in the NFC Card Emulation (CE) subsystem; crash dumps or tombstones referencing ce_t4t.cc or ce_t4t_data_cback on affected Android versions should be treated as high-priority indicators

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.