Missing Permission Check in Audio Service of Unisoc Products
CVE-2022-48246

7.8HIGH

What is CVE-2022-48246?

A vulnerability exists in the audio service of Unisoc products, where a missing permission check may allow local escalation of privilege. This flaw could exploit existing permissions without the need for additional execution privileges, potentially compromising system integrity and user privacy.

Affected Version(s)

SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 Android10/Android11/Android12/Android13

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.