CVE-2022-20234Incorrect Permission Assignment in Google Android

Severity
7.5HIGHNVD
EPSS
0.1%
top 70.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 13
Latest updateJul 14

Description

In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, it gets both 'mComponentName' and 'pkgTitle' from user.An unprivileged app can use a malicous mComponentName with a benign pkgTitle (e.g. Settings app) to make users enable notification access permission for the malicious app. That is, users believe they enable the notification access permission for the Settings app, but actually they enable the notification access permission f

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5google/androidAndroid-12L
NVDgoogle/android12.1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-v2x4-9328-wv22: In Car Settings app, the NotificationAccessConfirmationActivity is exported2022-07-14