CVE-2022-20004
HIGHAndroid - Local Privilege Escalation via Slice URI Input Validation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-20004. PoCs published by Trinadh465.
AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2022-20004, an Android autofill vulnerability. The code includes test cases and a custom autofill service to demonstrate the issue.
Description
In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-179699767
Exploits (1)
This repository contains a proof-of-concept for CVE-2022-20004, an Android autofill vulnerability. The code includes test cases and a custom autofill service to demonstrate the issue.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H