CVE-2022-20073: Google Android

Medium severity, CVSS 6.6. EPSS: 0.2% chance of exploitation in the next 30 days.

In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160841; Issue ID: ALPS06160841.

Affected products

  • Google Android: version 10.0 only; version 11.0 only; version 12.0 only

Published 2022-04-11. Last modified 2026-06-17.