Modification of Assumed-Immutable Data (MAID) Affecting com.google.android.gms:play-services-basement package, versions [,18.0.2)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-COMGOOGLEANDROIDGMS-2987459
  • published19 Aug 2022
  • disclosed13 Aug 2022
  • creditUnknown

Introduced: 13 Aug 2022

CVE-2022-2390  (opens in a new tab)
CWE-471  (opens in a new tab)

How to fix?

Upgrade com.google.android.gms:play-services-basement to version 18.0.2 or higher.

Overview

Affected versions of this package are vulnerable to Modification of Assumed-Immutable Data (MAID). Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all non-exported providers and/or gain the access to other providers the victim has permissions.

CVSS Scores

version 3.1