CVE-2022-39912

MEDIUM

Google Android < 13.0 - Improper Exception Handling

Title source: rule

Description

Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

Scores

CVSS v3 6.2
EPSS 0.0001
EPSS Percentile 1.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-755 CWE-280
Status published

Affected Products (1)

google/android < 13.0

Timeline

Published Dec 08, 2022
Tracked Since Feb 18, 2026