CVE-2022-38670
published 2022-10-14CVE-2022-38670: In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.16%
5.4th percentile
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| unisoc_technologies_co_ltd | sc9863a_sc9832e_sc7731e_t610_t310_t606_t760_t610_t618_t606_t612_t616_t760_t770_t | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2022-38670: Android
vendor_android·2022-11-01·CVSS 7.8
CVE-2022-38670 [HIGH] CVE-2022-38670: Android
Android Security Bulletin 2022-11-01
CVE: CVE-2022-38670
Severity: HIGH
Component: Android
References: A-244674480
U-1883755
*
OSV
CVE-2022-38669: In soundrecorder service, there is a missing permission check
osv·2022-11-01
CVE-2022-38669 CVE-2022-38669: In soundrecorder service, there is a missing permission check
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
GHSA
GHSA-223q-gr4m-8xc3: In soundrecorder service, there is a missing permission check
ghsa_unreviewed·2022-10-15
CVE-2022-38670 [HIGH] CWE-862 GHSA-223q-gr4m-8xc3: In soundrecorder service, there is a missing permission check
In soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in contacts service with no additional execution privileges needed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-14
Published