CVE-2022-20007
HIGHAndroid - Local Privilege Escalation via Race Condition in RootWindowContainer
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2022-20007. PoCs published by Trinadh465, pazhanivel07.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2022-20007, targeting Android's autofill framework. The code demonstrates performance tests that manipulate autofill behavior, potentially leading to privilege escalation or information disclosure.
Description
In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-211481342
Exploits (2)
This repository contains a proof-of-concept exploit for CVE-2022-20007, targeting Android's autofill framework. The code demonstrates performance tests that manipulate autofill behavior, potentially leading to privilege escalation or information disclosure.
This repository contains a proof-of-concept exploit for CVE-2022-20007, targeting Android's autofill framework. The code includes test cases demonstrating the vulnerability, which involves improper handling of autofill requests, potentially leading to information disclosure or unauthorized actions.
References (1)
Scores
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H