Vulnerabilities > CVE-2022-27836 - Incorrect Authorization vulnerability in Google Android 12.0
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary files access.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 |