CVE-2022-20416

HIGH

Android -12, -12L, -13 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In audioTransportsToHal of HidlUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237717857

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (3)
google/android 12.0
google/android 12.1
google/android 13.0
Published Oct 11, 2022
Tracked Since Feb 18, 2026