CVE-2022-20496
published 2022-12-13CVE-2022-20496: In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local information…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.13%
3.0th percentile
In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-245242273
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_av | >= 12:0 < 12:2022-12-01 | 12:2022-12-01 |
| platform | frameworks_av | >= 12L:0 < 12L:2022-12-01 | 12L:2022-12-01 |
| platform | frameworks_av | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 12.0/13.0 initMediaExtractor.cpp setDataSource use after free (A-245242273 / EUVD-2022-25756)
vuldb·2026-04-18·CVSS 5.5
CVE-2022-20496 [MEDIUM] Google Android 12.0/13.0 initMediaExtractor.cpp setDataSource use after free (A-245242273 / EUVD-2022-25756)
A vulnerability was found in Google Android 12.0/13.0 and classified as problematic. This affects the function setDataSource of the file initMediaExtractor.cpp. The manipulation results in use after free.
This vulnerability is known as CVE-2022-20496. Attacking locally is a requirement. No exploit is available.
Applying a patch is advised to resolve this issue.
GHSA
GHSA-76mx-8chc-6m73: In setDataSource of initMediaExtractor
ghsa_unreviewed·2022-12-13
CVE-2022-20496 [MEDIUM] CWE-416 GHSA-76mx-8chc-6m73: In setDataSource of initMediaExtractor
In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-245242273
OSV
CVE-2022-20496: In setDataSource of initMediaExtractor
osv·2022-12-01
CVE-2022-20496 CVE-2022-20496: In setDataSource of initMediaExtractor
In setDataSource of initMediaExtractor.cpp, there is a possibility of arbitrary code execution due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2022-20496: Android Security Bulletin 2022-12-01
CVE: CVE-2022-20496
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L, 13
References: A-245242273
vendor_android·2022-12-01·CVSS 5.5
CVE-2022-20496 [MEDIUM] CVE-2022-20496: Android Security Bulletin 2022-12-01
CVE: CVE-2022-20496
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L, 13
References: A-245242273
Android Security Bulletin 2022-12-01
CVE: CVE-2022-20496
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L, 13
References: A-245242273
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-13
Published