CVE-2022-20425
published 2022-10-11CVE-2022-20425: In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
2.8th percentile
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235823407
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 10:0 < 10:2022-10-01 | 10:2022-10-01 |
| platform | frameworks_base | >= 11:0 < 11:2022-10-01 | 11:2022-10-01 |
| platform | frameworks_base | >= 12:0 < 12:2022-10-01 | 12:2022-10-01 |
| platform | frameworks_base | >= 12L:0 < 12L:2022-10-01 | 12L:2022-10-01 |
| platform | frameworks_base | >= 13:0 < 13:2022-10-01 | 13:2022-10-01 |
| platform | packages_apps_settings | >= 10:0 < 10:2022-10-01 | 10:2022-10-01 |
| platform | packages_apps_settings | >= 11:0 < 11:2022-10-01 | 11:2022-10-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android denial of service (A-235823407 / EUVD-2022-25685)
vuldb·2026-04-14·CVSS 5.5
CVE-2022-20425 [MEDIUM] Google Android denial of service (A-235823407 / EUVD-2022-25685)
A vulnerability classified as problematic was found in Google Android. This affects an unknown function. Such manipulation leads to denial of service.
This vulnerability is referenced as CVE-2022-20425. The attack needs to be initiated within the local network. No exploit is available.
A patch should be applied to remediate this issue.
VulDB
Google Android 10.0/11.0/12.0/13.0 ZenModeHelper.java addAutomaticZenRule resource consumption (A-235823407 / EUVD-2022-25685)
vuldb·2026-04-13·CVSS 5.5
CVE-2022-20425 [MEDIUM] Google Android 10.0/11.0/12.0/13.0 ZenModeHelper.java addAutomaticZenRule resource consumption (A-235823407 / EUVD-2022-25685)
A vulnerability was found in Google Android 10.0/11.0/12.0/13.0. It has been declared as problematic. This affects the function addAutomaticZenRule of the file ZenModeHelper.java. The manipulation results in resource consumption.
This vulnerability is identified as CVE-2022-20425. The attack is only possible with local access. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
GHSA
GHSA-g8m9-2vr9-w7f7: In addAutomaticZenRule of ZenModeHelper
ghsa_unreviewed·2022-10-12
CVE-2022-20425 [MEDIUM] CWE-400 GHSA-g8m9-2vr9-w7f7: In addAutomaticZenRule of ZenModeHelper
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-235823407
OSV
CVE-2022-20425: In addAutomaticZenRule of ZenModeHelper
osv·2022-10-01
CVE-2022-20425 CVE-2022-20425: In addAutomaticZenRule of ZenModeHelper
In addAutomaticZenRule of ZenModeHelper.java, there is a possible permanent degradation of performance due to resource exhaustion. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2022-20425: Android Security Bulletin 2022-10-01
CVE: CVE-2022-20425
Severity: HIGH
Type: DoS
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-235823407
vendor_android·2022-10-01·CVSS 5.5
CVE-2022-20425 [MEDIUM] CVE-2022-20425: Android Security Bulletin 2022-10-01
CVE: CVE-2022-20425
Severity: HIGH
Type: DoS
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-235823407
Android Security Bulletin 2022-10-01
CVE: CVE-2022-20425
Severity: HIGH
Type: DoS
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-235823407
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published