CVE-2022-20513
published 2022-12-16CVE-2022-20513: In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.21%
10.8th percentile
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244569759
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | frameworks_av | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 13.0 CryptoPlugin.cpp decrypt_1_2 out-of-bounds (A-244569759 / EUVD-2022-25773)
vuldb·2026-04-20·CVSS 5.5
CVE-2022-20513 [MEDIUM] Google Android 13.0 CryptoPlugin.cpp decrypt_1_2 out-of-bounds (A-244569759 / EUVD-2022-25773)
A vulnerability identified as problematic has been detected in Google Android 13.0. Affected by this vulnerability is the function decrypt_1_2 of the file CryptoPlugin.cpp. The manipulation leads to out-of-bounds read.
This vulnerability is traded as CVE-2022-20513. An attack has to be approached locally. There is no exploit available.
Applying a patch is the recommended action to fix this issue.
GHSA
GHSA-g583-4mg8-hq84: In decrypt_1_2 of CryptoPlugin
ghsa_unreviewed·2022-12-20
CVE-2022-20513 [MEDIUM] CWE-125 GHSA-g583-4mg8-hq84: In decrypt_1_2 of CryptoPlugin
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-244569759
OSV
CVE-2022-20513: In decrypt_1_2 of CryptoPlugin
osv·2022-12-01
CVE-2022-20513 CVE-2022-20513: In decrypt_1_2 of CryptoPlugin
In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-16
Published