CVE-2022-20394 is a local information disclosure vulnerability affecting Android versions 10 through 12L. It allows an attacker to determine if another application is displaying an Input Method Editor (IME) due to a missing permission check in InputMethodManagerService.java. Rated with a CVSS score of 5.0 (Medium), exploitation requires user interaction and local access, but no additional execution privileges. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the KEV catalog. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* | ||
12.1CPE matchmatch criteria | cpe:2.3:o:google:android:12.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.