Beveiligingsadvies

CVE-2022-20303

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-08-11 15:22:11
Laatst bijgewerkt 2024-08-03 02:10:44
Toegewezen door google_android
CVSS-score geen score
Status PUBLISHED

Beschrijving

In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-200573021