Lucene search

K
osvGoogleOSV:ASB-A-197296414
HistoryMay 01, 2023 - 12:00 a.m.

Toasts can still be made touchable

2023-05-0100:00:00
Google
osv.dev
7
toasts
inputdispatcher
clickable
touchable
tapjacking
overlay attack
local privilege escalation
user interaction

0 Low

EPSS

Percentile

0.0%

In several functions of inputDispatcher.cpp, there is a possible way to make toasts clickable due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

0 Low

EPSS

Percentile

0.0%

Related for OSV:ASB-A-197296414