CVE-2022-2390 describes a vulnerability in applications built with the Google Play Services SDK, where PendingIntents passed to the Notification service incorrectly had the mutability flag set. This widespread issue affects numerous applications utilizing the SDK. With a CVSS score of 8.4 (HIGH), an attacker could gain access to non-exported and other permitted providers, leading to high confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog. Organizations are advised to upgrade to Play Services SDK version 18.0.2 and redeploy affected applications.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.0.2CPE matchmatch criteria | cpe:2.3:a:google:google_play_services_software_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.