CVE-2022-20418
published 2022-10-11CVE-2022-20418: In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.44%
35.3th percentile
In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-231986464
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_av | >= 12:0 < 12:2022-10-01 | 12:2022-10-01 |
| platform | frameworks_av | >= 12L:0 < 12L:2022-10-01 | 12L:2022-10-01 |
| platform | frameworks_av | >= 13:0 < 13:2022-10-01 | 13:2022-10-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android information disclosure (A-231986464 / EUVD-2022-25678)
vuldb·2026-04-13·CVSS 7.5
CVE-2022-20418 [HIGH] Google Android information disclosure (A-231986464 / EUVD-2022-25678)
A vulnerability was found in Google Android. It has been rated as problematic. Affected by this issue is some unknown functionality. This manipulation causes information disclosure.
This vulnerability appears as CVE-2022-20418. The attacker needs to be present on the local network. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.
VulDB
Google Android 12.0/13.0 AAVCAssembler.cpp pickStartSeq out-of-bounds (A-231986464 / EUVD-2022-25678)
vuldb·2026-04-13·CVSS 7.5
CVE-2022-20418 [HIGH] Google Android 12.0/13.0 AAVCAssembler.cpp pickStartSeq out-of-bounds (A-231986464 / EUVD-2022-25678)
A vulnerability classified as problematic has been found in Google Android 12.0/13.0. The affected element is the function pickStartSeq of the file AAVCAssembler.cpp. This manipulation causes out-of-bounds read.
This vulnerability is handled as CVE-2022-20418. The attack can be initiated remotely. There is not any exploit available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-gw8v-x559-3hvm: In pickStartSeq of AAVCAssembler
ghsa_unreviewed·2022-10-12
CVE-2022-20418 [HIGH] CWE-125 GHSA-gw8v-x559-3hvm: In pickStartSeq of AAVCAssembler
In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-231986464
OSV
CVE-2022-20418: In pickStartSeq of AAVCAssembler
osv·2022-10-01
CVE-2022-20418 CVE-2022-20418: In pickStartSeq of AAVCAssembler
In pickStartSeq of AAVCAssembler.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2022-20418: Android Security Bulletin 2022-10-01
CVE: CVE-2022-20418
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L, 13
References: A-231986464
vendor_android·2022-10-01·CVSS 7.5
CVE-2022-20418 [HIGH] CVE-2022-20418: Android Security Bulletin 2022-10-01
CVE: CVE-2022-20418
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L, 13
References: A-231986464
Android Security Bulletin 2022-10-01
CVE: CVE-2022-20418
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L, 13
References: A-231986464
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published