VDB

CVE-2022-29580

CVE-2022-29580 PUBLISHED CVSS 8.899999618530273 HIGH

There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of uri.getLastPathSegment. A symbolic encoded string can bypass the path logic to get access to unintended directories. An attacker can manipulate paths that could lead to code execution on the device. We recommend upgrading beyond version 13.41

EPSS 0.39% · 33.0th percentile

Risk Scores

CVSS 3.1
8.899999618530273
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
EPSS Score
0.39%
33.0th percentile

Affected Products

VendorProductVersions
googlegoogle_search0
GoogleAndroid Google Search App10.61

Timeline

  • Dec 13, 2022 CVE Published
  • Dec 14, 2022 EPSS Score
  • Jan 25, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 8, 2023 EPSS Score
  • Apr 19, 2023 EPSS Score
  • May 31, 2023 EPSS Score
  • Jul 13, 2023 EPSS Score
  • Aug 24, 2023 EPSS Score
  • Oct 5, 2023 EPSS Score
  • Nov 16, 2023 EPSS Score
  • Dec 28, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›