Google LLC Vulnerabilities and Affected Products
Vulnerabilities associated with Play Services SDK.
Products
Clear product- Asylo16 vulnerabilities
- Dart SDK4 vulnerabilities
- fscrypt3 vulnerabilities
- guest-oslogin3 vulnerabilities
- AWS S3 Crypto SDK for GoLang2 vulnerabilities
- Fuchsia2 vulnerabilities
- Fuchsia Kernel2 vulnerabilities
- libjxl2 vulnerabilities
- Android Play Core1 vulnerability
- Bazel1 vulnerability
- Bindiff1 vulnerability
- Brotli1 vulnerability
- Dart1 vulnerability
- Data-Transfer-Project1 vulnerability
- Drive for Desktop MacOS1 vulnerability
- Exposure Notifications Verification Server1 vulnerability
- Gerrit1 vulnerability
- go-attestation1 vulnerability
- Google Cloud IoT Device SDK for Embedded C1 vulnerability
- Google Earth Pro1 vulnerability
- Google Exposure-notifications-verification-server1 vulnerability
- Google Play Services SDK1 vulnerability
- Google-oauth-java-client1 vulnerability
- google-protobuf [JRuby Gem]1 vulnerability
- google/go-tpm library1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-2390MEDIUM | Mutable pending intent in Google Play services SDKApps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all non-exported providers and/or gain the access to other providers the victim has permissions. We recommend upgrading to version 18.0.2 of the Play Service SDK as well as rebuilding and … CWE-471Aug 12, 2022 | CVSS6.1v3.1 | EPSS0.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |