ASB-A-154015447
Dashboard / Vulnerabilities / ASB-A-154015447
Summary:
Details: In PackageInstaller, there is a possible tapjacking attack due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.
References: https://source.android.com/security/bulletin/2021-02-01, https://android.googlesource.com/platform/packages/apps/PackageInstaller/+/8c5b4cd30a77733dd1012725b69d2089f78455ac, https://android.googlesource.com/platform/packages/apps/Settings/+/4794b798c427c53a9d0f8c608c367a3e6469ed5f, https://android.googlesource.com/platform/packages/apps/Settings/+/7359b3840f06ef75c70d75a5708011fef25a2bab
Affected packages
Package
Name: platform/packages/apps/PackageInstaller
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
