Lucene search

K
osvGoogleOSV:ASB-A-205150380
HistoryMar 01, 2022 - 12:00 a.m.

Set Credential Manager App without User Consent

2022-03-0100:00:00
Google
osv.dev
6

0.0005 Low

EPSS

Percentile

17.6%

In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.

0.0005 Low

EPSS

Percentile

17.6%

Related for OSV:ASB-A-205150380