CVE-2022-20117 is a medium-severity vulnerability affecting the Android kernel, specifically related to improperly used cryptography within the GSC that could allow local data decryption. This flaw carries a CVSS score of 5.5, indicating a low attack complexity and no user interaction required, leading to potential local information disclosure. While there is no known public exploit code or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion and media coverage, with reports of Google patching an actively exploited Android kernel vulnerability, though it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.