CVE-2022-20431Missing Authorization in Google Android

Severity
7.8HIGHNVD
EPSS
0.0%
top 97.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 11
Latest updateApr 14

Description

There is an missing authorization issue in the system service. Since the component does not have permission check , resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242221238

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

5
VulDB
Google Android System Service authorization (A-242221238 / EUVD-2022-25691)2026-04-14
VulDB
Google Android authorization (A-242221238/U-1882896 / EUVD-2022-25691)2026-04-14
GHSA
GHSA-mj97-hr52-9xx5: There is an missing authorization issue in the system service2022-10-12
OSV
CVE-2022-20430: There is an missing authorization issue in the system service2022-10-01
OSV
CVE-2022-20430: There is an missing authorization issue in the system service2022-10-01

📋Vendor Advisories

1
Android
CVE-2022-20431: Telephony2022-10-01