CVE-2022-22286

MEDIUM

Bixby Routines <3.1.21.8 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows attackers to execute privileged action by hijacking and modifying the intent.

References (1)

Core 1
Core References

Scores

CVSS v3 4.4
EPSS 0.0011
EPSS Percentile 28.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-94
Status published
Products (1)
samsung/bixby_routines < 3.1.21.8
Published Jan 10, 2022
Tracked Since Feb 18, 2026