CVE-2022-39912

MEDIUM

Android < 13.0 - Improper Handling of Insufficient Permissions in PersonaManagerService

Title source: llm
STIX 2.1

Description

Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

References (1)

Core 1

Scores

CVSS v3 6.2
EPSS 0.0008
EPSS Percentile 0.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-755 CWE-280
Status published
Products (1)
google/android < 13.0
Published Dec 08, 2022
Tracked Since Feb 18, 2026