In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-154015447
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2924 | In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10Android ID: A-154015447 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://source.android.com/security/bulletin/2021-02-01 |
|
History
No history.
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2024-08-03T15:32:10.619Z
Reserved: 2020-11-06T00:00:00
Link: CVE-2021-0305
No data.
Status : Modified
Published: 2021-02-10T17:15:17.553
Modified: 2024-11-21T05:42:27.783
Link: CVE-2021-0305
No data.
OpenCVE Enrichment
No data.
EUVD