CVE-2022-20120 is a critical vulnerability affecting the Android kernel, impacting all Android versions. This vulnerability, rated 9.8 CRITICAL on CVSS, allows for remote, unauthenticated attacks with low complexity, leading to complete compromise of confidentiality, integrity, and availability. While there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community attention with 12 mentions and has been covered by major cybersecurity news outlets, indicating its importance. The EPSS score is low, but media reports suggest it was actively exploited at the time of discovery.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.