CVE-2022-20419
published 2022-10-11CVE-2022-20419: In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher process due to a logic error in the code. This could lead…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.10%
1.2th percentile
In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher process due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-237290578
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 12L:0 < 12L:2022-10-01 | 12L:2022-10-01 |
| platform | frameworks_base | >= 13:0 < 13:2022-10-01 | 13:2022-10-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android information disclosure (A-237290578 / EUVD-2022-25679)
vuldb·2026-04-13·CVSS 7.8
CVE-2022-20419 [HIGH] Google Android information disclosure (A-237290578 / EUVD-2022-25679)
A vulnerability classified as problematic was found in Google Android. Impacted is an unknown function. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2022-20419. The attack can only be performed from the local network. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
VulDB
Google Android 12.0/13.0 ActivityRecord.java setOptions Local Privilege Escalation (A-237290578 / EUVD-2022-25679)
vuldb·2026-04-13·CVSS 7.8
CVE-2022-20419 [HIGH] Google Android 12.0/13.0 ActivityRecord.java setOptions Local Privilege Escalation (A-237290578 / EUVD-2022-25679)
A vulnerability was found in Google Android 12.0/13.0. It has been classified as problematic. This affects the function setOptions of the file ActivityRecord.java. Performing a manipulation results in Local Privilege Escalation.
This vulnerability was named CVE-2022-20419. The attack needs to be approached locally. There is no available exploit.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-3f47-gwjx-9v4f: In setOptions of ActivityRecord
ghsa_unreviewed·2022-10-12
CVE-2022-20419 [HIGH] GHSA-3f47-gwjx-9v4f: In setOptions of ActivityRecord
In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher process due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-237290578
OSV
CVE-2022-20419: In setOptions of ActivityRecord
osv·2022-10-01
CVE-2022-20419 CVE-2022-20419: In setOptions of ActivityRecord
In setOptions of ActivityRecord.java, there is a possible load any arbitrary Java code into launcher process due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2022-20419: Android Security Bulletin 2022-10-01
CVE: CVE-2022-20419
Severity: CRITICAL
Type: ID
Affected AOSP versions: 12L, 13
References: A-237290578
vendor_android·2022-10-01·CVSS 7.8
CVE-2022-20419 [HIGH] CVE-2022-20419: Android Security Bulletin 2022-10-01
CVE: CVE-2022-20419
Severity: CRITICAL
Type: ID
Affected AOSP versions: 12L, 13
References: A-237290578
Android Security Bulletin 2022-10-01
CVE: CVE-2022-20419
Severity: CRITICAL
Type: ID
Affected AOSP versions: 12L, 13
References: A-237290578
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published