CVE-2022-20489

HIGH

Android - Local Privilege Escalation via Resource Exhaustion in AutomaticZenRule

Title source: llm
STIX 2.1

Description

In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242703460

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0027
EPSS Percentile 19.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-770
Status published
Products (5)
google/android 10.0
google/android 11.0
google/android 12.0
google/android 12.1
google/android 13.0
Published Jan 26, 2023
Tracked Since Feb 18, 2026