CVE-2022-20393

MEDIUM

Android 11-12L - Local Information Disclosure via Integer Overflow in TextDescriptions.cpp

Title source: llm
STIX 2.1

Description

In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure from the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-233735886

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://source.android.com/security/bulletin/2022-09-01

Scores

CVSS v3 5.5
EPSS 0.0009
EPSS Percentile 0.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-191
Status published
Products (3)
google/android 11.0
google/android 12.0
google/android 12.1
Published Sep 13, 2022
Tracked Since Feb 18, 2026