Fiche vulnérabilité
CVE-2021-0315 : faille élevée Android (CVSS 7.3)
Description
In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-169763814.
En bref
- Sévérité
- Élevée (CVSS 7.3)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 11 janv. 2021
- Dernière mise à jour
- 3 août 2024
Produits concernés
- Android
Preuves de concept publiques
Code tiers non vérifié : à n’exécuter qu’en environnement isolé.