
Cloud Vulnerability DB
A community-led vulnerabilities database
In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a missing permission check in Android 13. This vulnerability (CVE-2022-20335) could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation (MISC).
The vulnerability stems from a missing permission check in the Settings component of Android 13, specifically related to WiFi QR code content access. The issue allows unauthorized applications to read WiFi QR code content without having the necessary permissions. This represents a security control bypass that could expose sensitive network configuration information (MISC).
The successful exploitation of this vulnerability could lead to local information disclosure, potentially exposing sensitive WiFi network configuration details to unauthorized applications. While no additional execution privileges are required for exploitation, user interaction is necessary (MISC).
The vulnerability was addressed in Android 13. Users should ensure their devices are updated to the latest available security patch level that includes fixes for this issue (MISC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."