CVE-2022-20436Incorrect Default Permissions in Google Android

Severity
7.8HIGHNVD
EPSS
0.0%
top 97.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 11
Latest updateOct 12

Description

There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242248369

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-rmfp-7h73-4x4v: There is an unauthorized service in the system service2022-10-12
OSV
CVE-2022-20435: There is an unauthorized service in the system service2022-10-01
OSV
CVE-2022-20435: There is a Unauthorized service in the system service, may cause the system reboot2022-10-01

📋Vendor Advisories

1
Android
CVE-2022-20436: Android2022-10-01