CVE-2022-20559
published 2022-12-16CVE-2022-20559: In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to…
PriorityP47low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.12%
2.0th percentile
In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-219739967
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 13.0 PermissionManager.java revokeOwnPermissionsOnKill information exposure (A-219739967 / EUVD-2022-25819)
vuldb·2026-04-22·CVSS 3.3
CVE-2022-20559 [LOW] Google Android 13.0 PermissionManager.java revokeOwnPermissionsOnKill information exposure (A-219739967 / EUVD-2022-25819)
A vulnerability, which was classified as problematic, was found in Google Android 13.0. The affected element is the function revokeOwnPermissionsOnKill of the file PermissionManager.java. Such manipulation leads to information exposure through discrepancy.
This vulnerability is traded as CVE-2022-20559. An attack has to be approached locally. There is no exploit available.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-hwp7-wr93-75m3: In revokeOwnPermissionsOnKill of PermissionManager
ghsa_unreviewed·2022-12-21
CVE-2022-20559 [LOW] CWE-203 GHSA-hwp7-wr93-75m3: In revokeOwnPermissionsOnKill of PermissionManager
In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-219739967
OSV
CVE-2022-20559: In revokeOwnPermissionsOnKill of PermissionManager
osv·2022-12-01
CVE-2022-20559 CVE-2022-20559: In revokeOwnPermissionsOnKill of PermissionManager
In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-16
Published