VDB
ASB-A-209611539
ASB-A-209611539
PUBLISHED
In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| platform | packages/apps/ManagedProvisioning | 10:0, 10, 11 |
Timeline
- Mar 1, 2022 CVE Published
- May 15, 2026 CVE Updated