Lucene search

K
osvGoogleOSV:ASB-A-171221090
HistoryApr 01, 2021 - 12:00 a.m.

[DeviceChooserActivity Could be Overlaid to Trick User Into Associating a Rogue Companion Device]

2021-04-0100:00:00
Google
osv.dev
13

0.0004 Low

EPSS

Percentile

15.9%

In onCreate of DeviceChooserActivity.java, there is a possible way to bypass user consent when pairing a Bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege and pairing malicious devices with no additional execution privileges needed. User interaction is needed for exploitation.

0.0004 Low

EPSS

Percentile

15.9%

Related for OSV:ASB-A-171221090