VDB
CVE-2022-29580
CVE-2022-29580
PUBLISHED
CVSS 8.899999618530273 HIGH
There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An attacker can manipulate paths that could lead to code execution on the device. We recommend upgrading beyond version 13.41
EPSS 0.39% · 33.0th percentile
Risk Scores
CVSS 3.1
8.899999618530273
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
EPSS Score
0.39%
33.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| google_search | 0 | |
| Android Google Search App | 10.61 |
Timeline
- Dec 13, 2022 CVE Published
- Dec 14, 2022 EPSS Score
- Jan 25, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 8, 2023 EPSS Score
- Apr 19, 2023 EPSS Score
- May 31, 2023 EPSS Score
- Jul 13, 2023 EPSS Score
- Aug 24, 2023 EPSS Score
- Oct 5, 2023 EPSS Score
- Nov 16, 2023 EPSS Score
- Dec 28, 2023 EPSS Score