
CISA report on vulnerabilities: Improper crypto signature check (CVE-2022-1739): Lets fake apps install. • Mutable self-attestation (CVE-2022-1740): Hides malware in logs or hashes. • Hidden terminal emulator (CVE-2022-1741): Backdoor for root access. • Safe mode reboot trick (CVE-2022-1742): Drops into Android OS for full control. • Path traversal in files (CVE-2022-1743): Zip tricks execute code from election defs. • Unnecessary privileges (CVE-2022-1744): Apps run too high, easy escalation. • Technician card spoofing (CVE-2022-1745): Fake cards get admin rights. • Poll worker auth leak (CVE-2022-1746): Exposes keys for other machines. • Voter session forgery (CVE-2022-1747): Print unlimited ballots.
Post summary
The CISA bulletin lists a series of Android CVEs with detailed functional impacts, but provides no evidence of active exploitation, PoC, or mitigation steps.
