VDB
CVE-2022-20271
CVE-2022-20271
PUBLISHED
CVSS 7.800000190734863 HIGH
In PermissionController, there is a possible way to grant some permissions without user consent due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-207672635
EPSS 0.12% · 1.8th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.12%
1.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| android | 13.0 | |
| n/a | Android | * |
Timeline
- Aug 11, 2022 CVE Published
- Aug 12, 2022 EPSS Score
- Aug 17, 2022 EPSS Score
- Sep 27, 2022 EPSS Score
- Nov 12, 2022 EPSS Score
- Dec 29, 2022 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 31, 2023 EPSS Score
- Jul 1, 2023 EPSS Score
- Aug 16, 2023 EPSS Score
- Oct 2, 2023 EPSS Score