Impact
In the onCreate method of ContactsPickerActivity.kt a potential UI deception flaw allows a tapjacking or overlay attack to mislead the user. This exposure could reveal local contact information without requiring any additional execution privileges. The vulnerability directly affects how the activity displays sensitive data and can be exploited by an adversary presenting a malicious overlay over the system UI.
Affected Systems
The affected product is the Android operating system, specifically the ContactsPickerActivity within the system UI. No specific version ranges are provided in the data, so the vulnerability potentially applies to all releases containing this activity until a fix is published.
Risk and Exploitability
The CVSS score of 3.3 and an EPSS score of less than 1% indicate a low severity and low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The description states that user interaction is not required for exploitation, indicating that the vulnerability can be triggered autonomously by an overlay attacker. With no patch or mitigation instructions supplied by the vendor, the risk remains that local contact data could be leaked to any overlay-capable application on the device.
OpenCVE Enrichment