VDB
CVE-2022-2390
CVE-2022-2390
PUBLISHED
CVSS 6.099999904632568 MEDIUM
Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all non-exported providers and/or gain the access to other providers the victim has permissions. We recommend upgrading to version 18.0.2 of the Play Service SDK as well as rebuilding and redeploying apps.
EPSS 0.11% · 1.4th percentile
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
EPSS Score
0.11%
1.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Google LLC | Play Services SDK | unspecified |
| google_play_services_software_development_kit | 0 | |
| Maven | com.google.android.gms:play-services-basement | 0 |
Timeline
- Aug 12, 2022 CVE Published
- Aug 13, 2022 EPSS Score
- Sep 28, 2022 EPSS Score
- Nov 13, 2022 EPSS Score
- Dec 29, 2022 EPSS Score
- Feb 14, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 1, 2023 EPSS Score
- May 17, 2023 EPSS Score
- Jul 2, 2023 EPSS Score
- Aug 17, 2023 EPSS Score
- Oct 2, 2023 EPSS Score