VDB
CVE-2022-20266
CVE-2022-20266
PUBLISHED
CVSS 5 MEDIUM
In Companion, there is a possible way to keep a service running with elevated importance without showing foreground service notification due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-211757348
EPSS 0.10% · 1.2th percentile
Risk Scores
CVSS 3.1
5
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
EPSS Score
0.10%
1.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Android | Android-13 |
| android | 13.0 |
Timeline
- Aug 11, 2022 CVE Published
- Aug 12, 2022 EPSS Score
- Aug 16, 2022 EPSS Score
- Sep 27, 2022 EPSS Score
- Nov 12, 2022 EPSS Score
- Dec 29, 2022 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 31, 2023 EPSS Score
- Jul 1, 2023 EPSS Score
- Aug 16, 2023 EPSS Score
- Oct 2, 2023 EPSS Score