ASB-A-145728687
Dashboard / Vulnerabilities / ASB-A-145728687
Summary:
Details: In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app is brought to the foreground. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
References: https://source.android.com/security/bulletin/2021-02-01, https://android.googlesource.com/platform/frameworks/base/+/36bcc77337814d4d36e2b10eb062ac417d91611e, https://android.googlesource.com/platform/frameworks/base/+/4236b3e88fe444e2fbec7aa564fccf8b57c071dd, https://android.googlesource.com/platform/frameworks/base/+/6de34f8ee714691dbc3c089245bf832006826ebe, https://android.googlesource.com/platform/frameworks/base/+/8669ef385780b8415412407deec85539a1e7db98, https://android.googlesource.com/platform/frameworks/base/+/ee11625bb707c3512d4e44a35cc85b0bd14a2478
Affected packages
Package
Name: platform/frameworks/base
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
