CVE-2022-39107
published 2022-10-14CVE-2022-39107: In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution…
PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.1th percentile
In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| unisoc_technologies_co_ltd | sc9863a_sc9832e_sc7731e_t610_t310_t606_t760_t610_t618_t606_t612_t616_t760_t770_t | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Unisoc S8000 Soundrecorder Service permission (EUVD-2022-41653)
vuldb·2026-06-27·CVSS 7.8
CVE-2022-39107 [HIGH] Unisoc S8000 Soundrecorder Service permission (EUVD-2022-41653)
A vulnerability was found in Unisoc SC9863A, SC9832E, SC7731E, T610, T310, T606, T760, T610, T618, T606, T612, T616, T760, T770, T820 and S8000. It has been declared as critical. This affects an unknown function of the component Soundrecorder Service. Such manipulation leads to permission issues.
This vulnerability is traded as CVE-2022-39107. An attack has to be approached locally. There is no exploit available.
GHSA
GHSA-qjrh-w4q5-gwc2: In Soundrecorder service, there is a missing permission check
ghsa_unreviewed·2022-10-15
CVE-2022-39107 [HIGH] CWE-862 GHSA-qjrh-w4q5-gwc2: In Soundrecorder service, there is a missing permission check
In Soundrecorder service, there is a missing permission check. This could lead to elevation of privilege in Soundrecorder service with no additional execution privileges needed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-14
Published