CVE-2022-20452 is a high-severity elevation of privilege vulnerability in the Android Framework affecting Android 13. The flaw is located in initializeFromParcelLocked in BaseBundle.java and is described as a possible arbitrary code execution issue caused by a confused deputy condition. Improper handling of parcel-derived bundle state can allow a local attacker to induce privileged code to perform unsafe actions on the attacker's behalf. Successful exploitation can result in arbitrary code execution in a more privileged context and thereby enable local privilege escalation. No user interaction is required.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a full Android application exploit targeting Android 13 (API 32) and specifically exploits CVE-2022-20452 and CVE-2022-20474, which are vulnerabilities in the Android framework's Parcel serialization mechanism. The exploit is implemented as an Android app (LeakValue) and consists of several Java classes, AIDL interfaces, and supporting resources. The main exploit logic is in MainActivity.java, which orchestrates the attack by killing the system Settings app, leaking a privileged Binder handle (IApplicationThread) via a series of crafted Parcel objects, and then using this handle to execute code in the context of the Settings app (system privileges) by calling scheduleReceiver. The payload is a BroadcastReceiver (ShellcodeReceiver) that demonstrates code execution by running the 'id' command and reporting the result. The repository also includes a local test framework for debugging and mock classes for system services. The attack vector is local (requires app installation and execution on the target device). The exploit is operational and demonstrates real code execution as a privileged system app.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.