CVE-2022-20428 is an out-of-bounds write vulnerability in the Android kernel, affecting Google Android products. This flaw, stemming from a missing bounds check, allows for local escalation of privilege. With a CVSS score of 6.7 (Medium), exploitation requires System execution privileges but no user interaction, leading to high confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. However, it has garnered some community discussion and media coverage, including a mention in an article about Google's bug bounty program.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.