CVE-2022-20515
published 2022-12-16CVE-2022-20515: In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.17%
6.2th percentile
In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-220733496
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | packages_apps_settings | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 13.0 AccountTypePreferenceLoader.java onPreferenceClick information disclosure (A-220733496 / EUVD-2022-25775)
vuldb·2026-04-20·CVSS 5.5
CVE-2022-20515 [MEDIUM] Google Android 13.0 AccountTypePreferenceLoader.java onPreferenceClick information disclosure (A-220733496 / EUVD-2022-25775)
A vulnerability described as problematic has been identified in Google Android 13.0. This affects the function onPreferenceClick of the file AccountTypePreferenceLoader.java. Executing a manipulation can lead to information disclosure.
This vulnerability is registered as CVE-2022-20515. The attack needs to be launched locally. No exploit is available.
A patch should be applied to remediate this issue.
GHSA
GHSA-4377-hq3v-hgqh: In onPreferenceClick of AccountTypePreferenceLoader
ghsa_unreviewed·2022-12-20
CVE-2022-20515 [MEDIUM] CWE-610 GHSA-4377-hq3v-hgqh: In onPreferenceClick of AccountTypePreferenceLoader
In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-220733496
OSV
CVE-2022-20515: In onPreferenceClick of AccountTypePreferenceLoader
osv·2022-12-01
CVE-2022-20515 CVE-2022-20515: In onPreferenceClick of AccountTypePreferenceLoader
In onPreferenceClick of AccountTypePreferenceLoader.java, there is a possible way to retrieve protected files from the Settings app due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-16
Published