CVE-2021-0569UI Misrepresentation / Clickjacking in Google Android

Severity
5.0MEDIUMNVD
EPSS
0.0%
top 97.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 22
Latest updateMay 24

Description

In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking/overlay attack. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174045870

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:NExploitability: 1.3 | Impact: 3.6

Affected Packages3 packages

Androidplatform/packages_providers_contactsprovider11:011:2021-06-01
CVEListV5google/androidAndroid-11
NVDgoogle/android11.0

🔴Vulnerability Details

3
GHSA
GHSA-gx5m-c6q5-vhp7: In onStart of ContactsDumpActivity2022-05-24
CVEList
CVE-2021-0569: In onStart of ContactsDumpActivity2021-06-22
OSV
CVE-2021-0569: In onStart of ContactsDumpActivity2021-06-01
CVE-2021-0569 — UI Misrepresentation / Clickjacking | cvebase