PT-2023-12638 · Google · Android

CVE-2022-20214

·

Publicado

2023-01-24

·

Atualizado

2025-04-01

CVSS v3.1

4.7

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Android versions 10 through 12
Description The issue concerns a tapjacking attack vulnerability in the In Car Settings app, specifically with the toggle button in Modify system settings. This allows attackers to overlay the toggle button, enabling apps to modify system settings without user consent.
Recommendations For Android versions 10 through 12, consider disabling the Modify system settings toggle button in the In Car Settings app as a temporary workaround until a patch is available. Restrict access to system settings modifications to minimize the risk of exploitation.

Correção

Clickjacking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-20214

Produtos afetados

Android