SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-20214

In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack.

MEDIUM 4.7EPSS 0.23%

Does this matter?

Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.

Description

In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183411210

CVSS 3.1
4.7 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
EPSS
0.23% probability · 13th percentile
CISA KEV
Not listed
Weakness
CWE-1021
Affected
google/android
Source
security@android.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.