CVE-2022-1799

Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release.
References
Link Resource
https://developers.google.com/android/guides/releases#may_03_2022 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:google:google_play_services_software_development_kit:*:*:*:*:*:*:*:*

History

05 Aug 2022, 15:40

Type Values Removed Values Added
CPE cpe:2.3:a:google:google_play_services_software_development_kit:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE NVD-CWE-Other
References (MISC) https://developers.google.com/android/guides/releases#may_03_2022 - (MISC) https://developers.google.com/android/guides/releases#may_03_2022 - Release Notes, Vendor Advisory
First Time Google
Google google Play Services Software Development Kit

29 Jul 2022, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-29 10:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-1799

Mitre link : CVE-2022-1799

CVE.ORG link : CVE-2022-1799


JSON object : View

Products Affected

google

  • google_play_services_software_development_kit
CWE
NVD-CWE-Other CWE-501

Trust Boundary Violation