PT-2023-12638 · Google · Android
CVE-2022-20214
·
Publicado
2023-01-24
·
Atualizado
2025-04-01
CVSS v3.1
4.7
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions 10 through 12
Description
The issue concerns a tapjacking attack vulnerability in the In Car Settings app, specifically with the toggle button in Modify system settings. This allows attackers to overlay the toggle button, enabling apps to modify system settings without user consent.
Recommendations
For Android versions 10 through 12, consider disabling the Modify system settings toggle button in the In Car Settings app as a temporary workaround until a patch is available. Restrict access to system settings modifications to minimize the risk of exploitation.
Correção
Clickjacking
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Android