CVE-2022-20240 - CERT CVE
ID CVE-2022-20240
Sažetak In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-231496105
Reference
CVSS
Base: 2.3
Impact: 1.4
Exploitability:0.8
Pristup
VektorSloženostAutentikacija
LOCAL LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
LOW NONE NONE
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Zadnje važnije ažuriranje 22-04-2025 - 20:15
Objavljeno 13-12-2022 - 16:15