Source |
CVE Liste |
Identifiant |
8290765 |
Date de publication |
2022-12-13 16:15:14 (vue: 2022-12-13 18:06:55) |
Titre |
CVE-2021-39617 |
Texte |
In the user interface buttons of PermissionController, there is a possible way to bypass permissions dialogs due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-175190844 |
Notes |
|
Envoyé |
Oui |
Condensat |
12landroid 175190844 2021 39617 additional android androidversions: attack buttons bypass could cve dialogs due escalation execution exploitation id: interaction interface lead local needed permissioncontroller permissions possible privilege privileges product: tapjacking/overlay user way |
Tags |
Guideline
|
Stories |
|
Move |
|