
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability identified as CVE-2022-20002 was discovered in Android's incfs (incremental filesystem) component. The vulnerability affects Android 12L and was assigned Android ID A-198657657. The issue stems from a missing permission check that could allow mounting on arbitrary paths (Android Bulletin, CVE Details).
The vulnerability exists in the incfs component of Android, where a missing permission check could allow unauthorized mounting operations on arbitrary paths. The issue requires System execution privileges for exploitation, and notably, no user interaction is required for successful exploitation (CVE Details).
If successfully exploited, this vulnerability could lead to local escalation of privilege. The attack requires System execution privileges, making it a significant security concern for Android systems (CVE Details).
The vulnerability affects Android 12L systems. Users should ensure their devices are updated with the latest security patches provided through the Android security bulletin (Android Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."