CVE-2022-20558
published 2022-12-16CVE-2022-20558: In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. This could lead to…
PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCNILAN
EPSS
0.11%
1.5th percentile
In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-236264289
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | frameworks_opt_net_ims | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 13.0 DeviceCapabilityListener.java registerReceivers permission (A-236264289 / EUVD-2022-25818)
vuldb·2026-04-22·CVSS 3.3
CVE-2022-20558 [LOW] Google Android 13.0 DeviceCapabilityListener.java registerReceivers permission (A-236264289 / EUVD-2022-25818)
A vulnerability categorized as critical has been discovered in Google Android 13.0. This impacts the function registerReceivers of the file DeviceCapabilityListener.java. The manipulation results in permission issues.
This vulnerability is identified as CVE-2022-20558. The attack is only possible with local access. There is not any exploit available.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-hjjq-jc6w-mqf5: In registerReceivers of DeviceCapabilityListener
ghsa_unreviewed·2022-12-21
CVE-2022-20558 [LOW] CWE-863 GHSA-hjjq-jc6w-mqf5: In registerReceivers of DeviceCapabilityListener
In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-236264289
OSV
CVE-2022-20558: In registerReceivers of DeviceCapabilityListener
osv·2022-12-01
CVE-2022-20558 CVE-2022-20558: In registerReceivers of DeviceCapabilityListener
In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-16
Published