maven package report

Is com.google.android.gms:play-services-basement safe?

1 known vulnerability, worst severity MODERATE.

cvss
6.1

how bad it is if exploited, out of 10

epss
0.10%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-cm6r-892j-jv2g, the advisory selected below

// advisories

GHSA-cm6r-892j-jv2g

MODERATECVE-2022-2390

Apps developed with Google Play Services SDK incorrectly had the mutability flag set to PendingIntents that were passed to the Notification service. As Google Play services SDK is so widely used, this bug affects many applications. For an application affected, this bug will let the attacker, gain the access to all non-exported providers and/or gain the access to other providers the victim has perm

Affected
< 18.0.2
Fixed in
18.0.2
Weakness
CWE-471
Published
2022-08-13
Source
github

GHSANVDMITREreferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 02:49 UTC. The most recent advisory here was published 2022-08-13. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is com.google.android.gms:play-services-basement safe? maven package security report | CyberXYZ