CVE-2022-20214 is a tapjacking vulnerability affecting the Car Settings app on Android 10, 11, and 12. An attacker can overlay the "Modify system settings" toggle button, allowing malicious applications to gain system setting modification privileges without explicit user consent. This vulnerability has a CVSS score of 4.7 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction, and resulting in low integrity impact (unauthorized modification of system settings). There is no confidentiality or availability impact. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion or media coverage, suggesting low public awareness and exploitation interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.