CVE-2022-20331 describes a local escalation of privilege vulnerability affecting Android 13, where a malicious application can enable a work profile without user consent through a tapjacking or overlay attack. This high-severity vulnerability (CVSS 7.8) requires user interaction for exploitation, but no additional execution privileges are needed, allowing an attacker to gain significant control over the device. Despite its severity, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it shows no signs of active exploitation or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
13.0CPE matchmatch criteria | cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.