CVE-2022-39912

MEDIUM

Android < 13.0 - Improper Handling of Insufficient Permissions in PersonaManagerService

Title source: llm
STIX 2.1

Description

Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

References (1)

Core 1

Scores

CVSS v3 6.2
EPSS 0.0011
EPSS Percentile 1.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-280 CWE-755
Status published
Products (1)
google/android < 13.0
Published Dec 08, 2022
Tracked Since Feb 18, 2026