CVE-2022-33719 is a critical vulnerability affecting Google Android's baseband, stemming from improper input validation that can lead to an integer overflow and subsequent heap overflow. With a CVSS score of 9.8, it allows unauthenticated remote attackers to achieve high impact on confidentiality, integrity, and availability with low attack complexity. Although no public exploits, Metasploit modules, or KEV entries exist, and community discussion is minimal, the high CVSS score and FAUCET Risk Score of 77/100 indicate its severe potential. This vulnerability requires patching to mitigate the risk of remote code execution or denial of service.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:o:google:android:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:google:android:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:google:android:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.