CVE-2022-20004

HIGH

Android - Local Privilege Escalation via Slice URI Input Validation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-20004. PoCs published by Trinadh465.

AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2022-20004, an Android autofill vulnerability. The code includes test cases and a custom autofill service to demonstrate the issue.

Description

In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-179699767

Exploits (1)

nomisec WORKING POC
by Trinadh465 · poc
https://github.com/Trinadh465/frameworks_base_AOSP10_r33_CVE-2022-20004

This repository contains a proof-of-concept for CVE-2022-20004, an Android autofill vulnerability. The code includes test cases and a custom autofill service to demonstrate the issue.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Android AOSP10 r33
No auth needed
Prerequisites: Android device with autofill service enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://source.android.com/security/bulletin/2022-05-01

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 10.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (4)
google/android 10.0
google/android 11.0
google/android 12.0
google/android 12.1
Published May 10, 2022
Tracked Since Feb 18, 2026