VDB
ASB-A-169763814
ASB-A-169763814
PUBLISHED
In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| platform | frameworks/base | *, 8.0:0, 8.1:0 |
Timeline
- Jan 1, 2021 CVE Published
- May 15, 2026 CVE Updated