CVE-2022-2390
Last modified
CVE-2022-2390 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all non-exported providers and/or gain the access to other providers the victim has permissions. We recommend upgrading to version 18.0.2 of the Play Service SDK as well as rebuilding and redeploying apps.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Google Play Services Software Development Kit | < 18.0.2 |
References
- https://developers.google.com/android/guides/releases#may_03_2022Release Notes, Vendor Advisory
- https://developers.google.com/android/guides/releases#may_03_2022Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2390?
How severe is CVE-2022-2390?
How do I fix CVE-2022-2390?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-23888YzmCMS v6.3 was discovered to contain a Cross-Site Request F…8.8
- CVE-2022-23889The comment function in YzmCMS v6.3 was discovered as being …5.3
- CVE-2022-2389The Abandoned Cart Recovery for WooCommerce, Follow Up Email…4.3
- CVE-2022-23896Admidio 4.1.2 version is affected by stored cross-site scrip…5.4
- CVE-2022-23898MCMS v5.2.5 was discovered to contain a SQL injection vulner…9.8
- CVE-2022-23899MCMS v5.2.5 was discovered to contain a SQL injection vulner…9.8
- CVE-2022-23900A command injection vulnerability in the API of the Wavlink …9.8
- CVE-2022-23901A stack overflow re2c 2.2 exists due to infinite recursion i…9.8
- CVE-2022-23902Tongda2000 v11.10 was discovered to contain a SQL injection …9.8
- CVE-2022-23903A Cross Site Scripting (XSS) vulnerability exists in pearadm…5.4
- CVE-2022-23904Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site R…8
- CVE-2022-23906CMS Made Simple v2.2.15 was discovered to contain a Remote C…7.2
Are you affected by CVE-2022-2390?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
