CVE-2022-20430Missing Authorization in Google Android

Severity
7.8HIGHNVD
EPSS
0.0%
top 97.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 11
Latest updateApr 14

Description

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221233

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

5
VulDB
Google Android authorization (A-242221233/U-1882896 / EUVD-2022-25690)2026-04-14
VulDB
Google Android System Service authorization (A-242221233 / EUVD-2022-25690)2026-04-14
GHSA
GHSA-f6rq-vvxp-669r: There is an missing authorization issue in the system service2022-10-12
OSV
CVE-2022-20430: There is an missing authorization issue in the system service2022-10-01
OSV
CVE-2022-20430: There is an missing authorization issue in the system service2022-10-01

📋Vendor Advisories

1
Android
CVE-2022-20430: Telephony2022-10-01