ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google fixed Critical Remote Code Execution flaw in Android

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-20237
+3 in the same advisory: …20400 …20402 …20403
In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check.

In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-229621649References: N/A

NVD description · AI analysis pending
9.8<1%
  • google android
CVE-2022-20345
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check.

In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-230494481

NVD description · AI analysis pending
8.8<1%
  • google android
Full article215 words · extracted from securityaffairs.com · click to collapse

Google addressed a critical vulnerability in Android OS, tracked as CVE-2022-20345, that can be exploited to achieve remote code execution over Bluetooth.

Google has fixed a critical vulnerability, tracked as CVE-2022-20345, that affects the Android System component. The IT giant has fixed the flaw with the release of Android 12 and 12L updates.

Google did not disclose additional details about the vulnerability.

“The most severe vulnerability in this section could lead to remote code execution over Bluetooth with no additional execution privileges needed.” reads the security bulletin published by Google.

Google addressed the issue with the release of security patch levels ‘2022-08-01’ and ‘2022-08-05’.

The CVE-2022-20345 flaw is the only issue rated as critical fixed by Google this month.

All the remaining vulnerabilities have been rated as ‘high severity’. The flaws impact Framework, Media Framework, System, Kernel, Imagination Technologies, MediaTek, Unisoc and Qualcomm components.

Google also patched tens of security vulnerabilities in Google Pixel devices, including four critical remote code execution flaws tracked as:

CVEReferencesTypeSeverityComponent
CVE-2022-20237A-229621649 *RCECriticalModem
CVE-2022-20400A-225178325*RCECriticalModem
CVE-2022-20402A-218701042 *RCECriticalModem
CVE-2022-20403A-207975764 *RCECriticalModem

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Android)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/133956/security/android-critical-flaw-cve-2022-20345.html