CVE-2022-20465
published 2022-11-08CVE-2022-20465: In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen bypass due to a logic error in the code…
PriorityP419medium4.6CVSS 3.1
AVPACLPRNUINSUCNIHAN
EPSS
0.77%
51.5th percentile
In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-218500036
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 10:0 < 10:2022-11-01 | 10:2022-11-01 |
| platform | frameworks_base | >= 11:0 < 11:2022-11-01 | 11:2022-11-01 |
| platform | frameworks_base | >= 12:0 < 12:2022-11-01 | 12:2022-11-01 |
| platform | frameworks_base | >= 12L:0 < 12L:2022-11-01 | 12L:2022-11-01 |
| platform | frameworks_base | >= 13:0 < 13:2022-11-01 | 13:2022-11-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 10.0/11.0/12.0/13.0 KeyguardHostViewController.java dismiss/related Local Privilege Escalation (A-218500036 / EUVD-2022-25725)
vuldb·2026-04-16·CVSS 4.6
CVE-2022-20465 [MEDIUM] Google Android 10.0/11.0/12.0/13.0 KeyguardHostViewController.java dismiss/related Local Privilege Escalation (A-218500036 / EUVD-2022-25725)
A vulnerability classified as problematic was found in Google Android 10.0/11.0/12.0/13.0. Affected is the function dismiss/related of the file KeyguardHostViewController.java. The manipulation results in Local Privilege Escalation.
This vulnerability is cataloged as CVE-2022-20465. The attack must be initiated from a local position. Furthermore, there is an exploit available.
A patch should be applied to remediate this issue.
GHSA
GHSA-r77h-h23j-fv39: In dismiss and related functions of KeyguardHostViewController
ghsa_unreviewed·2022-11-09
CVE-2022-20465 [MEDIUM] CWE-276 GHSA-r77h-h23j-fv39: In dismiss and related functions of KeyguardHostViewController
In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-218500036
OSV
CVE-2022-20465: In dismiss and related functions of KeyguardHostViewController
osv·2022-11-01
CVE-2022-20465 CVE-2022-20465: In dismiss and related functions of KeyguardHostViewController
In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2022-20465: Android Security Bulletin 2022-11-01
CVE: CVE-2022-20465
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-218500036
vendor_android·2022-11-01·CVSS 4.6
CVE-2022-20465 [MEDIUM] CVE-2022-20465: Android Security Bulletin 2022-11-01
CVE: CVE-2022-20465
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-218500036
Android Security Bulletin 2022-11-01
CVE: CVE-2022-20465
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-218500036
No detection rules found.
No public exploits indexed.
Talos
Threat Source newsletter (Nov. 17, 2022): Hot off the press! The Snort 2023 Calendar is here
blogs_talos·2022-11-17
Threat Source newsletter (Nov. 17, 2022): Hot off the press! The Snort 2023 Calendar is here
## Threat Source newsletter (Nov. 17, 2022): Hot off the press! The Snort 2023 Calendar is here
Welcome to this week’s edition of the Threat Source newsletter.
It's everyone’s favorite time of year again and no, I don’t mean the impending holidays. The Snort 2023 calendar is finally here, and y’all, it’s a good one. Packed full of classic memes and punny Snorties, the calendar is sure to delight all year long. The Talos creative team really knocked it out of the park with these original designs. I won’t spoil the whole calendar and reveal too much, but I’ve shared a favorite below...
Want a copy? NEED a copy? Simply fill out our short survey here. Calendars will begin shipping after December 1, 2022. U.S. shipping only, available while supplies last.
## The one big thing
Contributed b
Talos
Threat Source newsletter (Nov. 17, 2022): Hot off the press! The Snort 2023 Calendar is here
blogs_talos·2022-11-17
Threat Source newsletter (Nov. 17, 2022): Hot off the press! The Snort 2023 Calendar is here
Welcome to this week’s edition of the Threat Source newsletter.
It's everyone’s favorite time of year again and no, I don’t mean the impending holidays. The Snort 2023 calendar is finally here, and y’all, it’s a good one. Packed full of classic memes and punny Snorties, the calendar is sure to delight all year long. The Talos creative team really knocked it out of the park with these original designs. I won’t spoil the whole calendar and reveal too much, but I’ve shared a favorite below...
Want a copy? NEED a copy? Simply fill out our short survey here. Calendars will begin shipping after December 1, 2022. U.S. shipping only, available while supplies last.
## The one big thing
Contributed by Chris Neal
This week Cisco Talos has published a blog detailing new variants and versions of L
Checkpoint
14th November– Threat Intelligence Report
blogs_checkpoint·2022-11-14
CVE-2022-20465 14th November– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th November– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The Australian Federal Police has disclosed that the hacking group responsible for the massive Medibank hack that compromised the personal information of 9.7 million customers is based in Russia. The group’s identity was not yet published.
Black Basta ransomware group has launched a cyberattack against Canadian grocery
Checkpoint
14th November– Threat Intelligence Report
blogs_checkpoint·2022-11-14
CVE-2022-20465 14th November– Threat Intelligence Report
Top Attacks and Breaches
The Australian Federal Police has disclosed that the hacking group responsible for the massive Medibank hack that compromised the personal information of 9.7 million customers is based in Russia. The group’s identity was not yet published.
Black Basta ransomware group has launched a cyberattack against Canadian grocery and pharmacy chain store Sobeys, impacting some of the company’s in-store services and operations.
Check Point Harmony Endpoint and Threat Emulation provide protection against this threat (Banker.Wins.Carbanak.*; Ransomware.Win.BlackBasta.*)
Security Researchers have disclosed two new surveillance campaigns targeting Uyghurs in the People’s Republic of China and abroad with BadBazaar and MOONSHINE spyware.
Threat actors are mass spreading scam e
2022-11-08
Published