CVE-2022-20312 — Missing Authorization in Google Android
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 96.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateAug 13
Description
In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check. This could lead to local information disclosure without additional execution privileges needed. User interaction is not needed forexploitationProduct: AndroidVersions: Android-13Android ID: A-192244925
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages2 packages
🔴Vulnerability Details
1GHSA▶
GHSA-c2xf-vw67-2qqr: In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check↗2022-08-13