Impact
A vulnerability in the onCreate method of InstallLaunch.kt enables a misleading user interface that may be exploited through tapjacking or overlay attacks. The flaw can lead to an escalation of privilege on the local device without granting any additional execution rights or requiring the attacker to gain code execution privileges. The CVE description indicates that user interaction is not needed for exploitation, meaning the attacker can craft an overlay that manipulates the user interface to perform privileged actions silently. The primary impact is a local privilege escalation that could allow the attacker to bypass normal application restrictions, access restricted data, or modify the device state covertly.
Affected Systems
The affected product is Android by Google. No specific version or build information is supplied in the data, so the vulnerability may affect a broad range of Android devices and installations. Because the issue resides in a core Android component, all current devices running the affected Android release are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score is not provided, but local privilege escalation typically carries a high severity rating. The EPSS score is unavailable, and the vulnerability is not currently listed in the CISA KEV catalog, which suggests limited known exploitation at this time. However, the lack of an explicit user interaction requirement means that an attacker with any local access to the device—including malicious applications with overlay permissions—could trigger the flaw. While no public exploit is referenced, the risk is considered moderate to high due to the potential for attackers to leverage the overlay to influence privileged functions without user awareness.
OpenCVE Enrichment