VDB

CVE-2022-2390

CVE-2022-2390 PUBLISHED CVSS 6.099999904632568 MEDIUM

Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all non-exported providers and/or gain the access to other providers the victim has permissions. We recommend upgrading to version 18.0.2 of the Play Service SDK as well as rebuilding and redeploying apps.

EPSS 0.11% · 1.4th percentile

Risk Scores

CVSS 3.1
6.099999904632568
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
EPSS Score
0.11%
1.4th percentile

Affected Products

VendorProductVersions
Google LLCPlay Services SDKunspecified
googlegoogle_play_services_software_development_kit0
Mavencom.google.android.gms:play-services-basement0

Timeline

  • Aug 12, 2022 CVE Published
  • Aug 13, 2022 EPSS Score
  • Sep 28, 2022 EPSS Score
  • Nov 13, 2022 EPSS Score
  • Dec 29, 2022 EPSS Score
  • Feb 14, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 1, 2023 EPSS Score
  • May 17, 2023 EPSS Score
  • Jul 2, 2023 EPSS Score
  • Aug 17, 2023 EPSS Score
  • Oct 2, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›