In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://source.android.com/security/bulletin/2022-08-01 |
![]() ![]() |
History
Mon, 20 Oct 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
ssvc
|
Mon, 20 Oct 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-125 |

Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2025-10-20T17:57:27.175Z
Reserved: 2021-10-14T00:00:00.000Z
Link: CVE-2022-20350

Updated: 2024-08-03T02:10:44.617Z

Status : Modified
Published: 2022-08-10T20:15:26.690
Modified: 2025-10-20T18:15:36.330
Link: CVE-2022-20350

No data.

No data.