CVE-2022-20362

HIGH

Android <13 - Remote Code Execution

Title source: llm
STIX 2.1

Description

In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-230756082

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0024
EPSS Percentile 14.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (1)
google/android 13.0
Published Aug 12, 2022
Tracked Since Feb 18, 2026