ASB-A-157929241 PUBLISHED

In WindowManager, there is a possible tapjacking attack due to an incorrect window flag when processing user input. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Affected Products

VendorProductVersions
platformpackages/apps/Launcher311:0, 11:0, 12
platformpackages/modules/Permission12L-next:0, 12L-next, 12L-next
platformframeworks/base11:0, 12L-next:0, 12L-next
platformframeworks/native11, *, 10

Timeline

References

Open in Interactive Console →