Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c4q-pqm9-78g4

Опубликовано: 26 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183411210

In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183411210

EPSS

Процентиль: 26%
0.0009
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 4.7
nvd
около 3 лет назад

In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183411210

EPSS

Процентиль: 26%
0.0009
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-1021