Impact
In the Android IntentForwarderActivity, the buildMiniResolver function is vulnerable to a tapjacking or overlay attack that can bypass consent prompts. An attacker can coerce or misdirect a device user without requiring any user interaction, allowing the malicious activity to gain higher privileges on the device. The vulnerability facilitates privilege escalation locally and does not require the attacker to obtain additional execution rights beyond the normal Android permission framework.
Affected Systems
All Android devices running the affected build of the Android operating system, including versions published by Google prior to the availability of a publicly released patch. No specific version strings are listed in the advisory.
Risk and Exploitability
The Exploit Propensity Scoring System provides a score of 0.00121 for this issue, indicating a very low probability of exploitation. The CVSS score of 7.8 denotes high severity, and the described local privilege escalation potential and lack of required user interaction suggest a moderate to high risk despite the low exploitation likelihood. The attack vector is inferred to be local, relying on a UI overlay, and the attacker would need to co-locate on the device—no remote exploitation is described.
OpenCVE Enrichment