Lucene search

K
osvGoogleOSV:ASB-A-313425281
HistoryJun 01, 2024 - 12:00 a.m.

Overlay HealthFitness#PermissionsActivity to trick user into allowing unexpected health permissions

2024-06-0100:00:00
Google
osv.dev
1
tapjacking
local privilege escalation
user interaction

7 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%

In onCreate of multiple files, there is a possible way to trick the user into granting health permissions due to tapjacking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

7 High

AI Score

Confidence

High

0 Low

EPSS

Percentile

0.0%