QID 610435

Date Published: 2022-09-15

QID 610435: Google Android August 2022 Security Patch Missing for Samsung

Android is a mobile operating system based on a modified version of the Linux kernel and other open source software, designed primarily for touchscreen mobile devices such as smartphones and tablets.

Following security issues were discovered:
CVE-2022-20345,CVE-2022-20083,CVE-2022-21744,CVE-2022-20236,CVE-2022-20238,CVE-2022-20220,CVE-2021-39696,CVE-2022-20344,CVE-2022-20348,CVE-2022-20349,CVE-2022-20356,CVE-2022-20350,CVE-2022-20352,CVE-2022-20357,CVE-2022-20358,CVE-2022-20346,CVE-2022-20353,CVE-2022-20347,CVE-2022-20354,CVE-2022-20360,CVE-2022-20361,CVE-2022-20355,CVE-2022-1786,CVE-2022-20082

Affected Products :
Galaxy Fold, Galaxy Fold 5G, Galaxy Z Fold2, Galaxy Z Fold2 5G, Galaxy Z Fold3 5G, Galaxy Z Flip, Galaxy Z Flip 5G, Galaxy Z Flip3 5G, Galaxy Z Fold4 , Galaxy Z Flip4 Galaxy S10 Lite Galaxy S20, Galaxy S20 5G, Galaxy S20+, Galaxy S20+ 5G, Galaxy S20 Ultra, Galaxy S20 Ultra 5G, Galaxy S20 FE, Galaxy S20 FE 5G, Galaxy S21 5G, Galaxy S21+ 5G, Galaxy S21 Ultra 5G, Galaxy S21 FE 5G, Galaxy S22, Galaxy S22+, Galaxy S22 Ultra Galaxy Note10 Lite, Galaxy Note20, Galaxy Note20 5G, Galaxy Note20 Ultra, Galaxy Note20 Ultra 5G Enterprise Models: Galaxy A52, Galaxy A52 5G, Galaxy A52s 5G, Galaxy A53 5G, Galaxy Xcover FieldPro, Galaxy Xcover Pro, Galaxy Xcover5, Galaxy Xcover6 Pro

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to Samsung Security advisory SMR-August-2022 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    SMR-August-2022 Android URL Logo security.samsungmobile.com/securityUpdate.smsb