Impact
A flaw in the onCreate routine of InstallLaunch.kt can display a misleading user interface that may be leveraged by tap‑jacking or overlay attacks. The vulnerability can allow a local adversary to execute privileged actions without obtaining additional code‑execution permissions or requiring the user to take any explicit action. The weakness, identified as CWE‑601, enables malicious manipulation of the interface that can elevate the attacker’s privileges on the device.
Affected Systems
Android devices that include the vulnerable InstallLaunch component are affected. The specific build version is not provided, so a broad range of current Android releases may be impacted until the fix is applied.
Risk and Exploitability
The severity score of 7.8 indicates a high potential impact, while the EPSS value of less than 1% suggests a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, implying no large‑scale attacks have been documented. Nevertheless, the low barrier to exploitation—only local presence of a malicious app with overlay permissions—is sufficient reason for swift remediation.
OpenCVE Enrichment