LiveActive security incident?Get immediate response
CVE Record

CVE-2022-48450: In bluetooth service, there is a possible missing params check.

In bluetooth service, there is a possible missing params check. This could lead to local denial of service with System execution privileges needed.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

This UNISOC Bluetooth service issue can cause a local denial of service, but the source says System execution privileges are needed. That means an attacker would already need deep local control before triggering the crash condition. Public severity, CVSS, patch details, and exploit evidence are not provided in the bundle.

Executive priority

Treat as a low immediate business priority unless your fleet includes affected UNISOC Android devices with unreliable patching. The main concern is operational disruption on already-compromised or highly privileged devices, not a clearly documented remote compromise path.

Technical view

CVE-2022-48450 describes a missing parameter check in the Bluetooth service affecting listed UNISOC chipsets on Android 10, 11, and 12. The documented impact is local denial of service with System privileges required. No CWE, CVSS vector, exploit method, or vendor remediation detail is included in the supplied data.

Likely exposure

Exposure is likely limited to Android devices using the listed UNISOC chipsets and Android 10 through 12 builds. Organizations should confirm actual device SoCs and OEM firmware levels because the bundle names chipsets, not specific phone models or patched build numbers.

Exploitation context

The bundle does not show active exploitation, and KEV is false. The stated requirement for System execution privileges materially limits practical abuse from ordinary apps or remote attackers. Evidence is insufficient to assess exploit maturity beyond the vendor/CVE description.

Researcher notes

The public record is sparse: missing parameter validation in Bluetooth service, local DoS impact, and System privilege requirement. Avoid assuming memory corruption, remote Bluetooth reachability, affected handset models, or patch identifiers without vendor or OEM confirmation.

Mitigation direction

  • Check UNISOC and device OEM advisories for fixed firmware builds.
  • Prioritize updates for managed devices using affected UNISOC chipsets.
  • Restrict administrative or System-level access on Android endpoints.
  • Retire unsupported Android 10 to 12 devices where updates are unavailable.

Validation and detection

  • Inventory Android devices for the listed UNISOC chipsets.
  • Map affected devices to Android 10, 11, or 12 builds.
  • Check OEM security patch levels against vendor guidance.
  • Review mobile EDR logs for repeated Bluetooth service crashes.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2022-48450 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Unisoc (Shanghai) Technologies Co., Ltd.SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000Android10/Android11/Android12unaffected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.