CVE-2022-1955

MEDIUM

Session 1.13.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Session 1.13.0 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.

References (3)

Core 3
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://fluidattacks.com/advisories/tempest/
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/oxen-io/session-android/pull/897
Product, Third Party Advisory x_refsource_misc
https://github.com/oxen-io/session-android

Scores

CVSS v3 4.6
EPSS 0.0035
EPSS Percentile 26.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (1)
opft/session 1.13.0
Published Jun 30, 2022
Tracked Since Feb 18, 2026