nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-20477 CVE-2022-20477
HIGH
Record summary
CVE-2022-20477 has a selected CVSS score of 7.8 (high).
Description
In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notifications due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-241611867
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Android | CVE List | Android-13 | affected |
References
2source.android.com
https://source.android.com/security/bulletin/2022-12-01