cbcvebase.
CVE-2021-39617
published 2023-05-01

CVE-2021-39617: In multiple buttons of grant_permissions.xml, there is a possible way to bypass permissions dialogs due to a tapjacking/overlay attack. This could lead to…

In multiple buttons of grant_permissions.xml, there is a possible way to bypass permissions dialogs due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Affected

10 ranges
VendorProductVersion rangeFixed in
googleandroid
platformframeworks_base>= 11:0 < 11:2023-05-0111:2023-05-01
platformframeworks_base>= 12:0 < 12:2023-05-0112:2023-05-01
platformframeworks_native>= 11:0 < 11:2023-05-0111:2023-05-01
platformframeworks_native>= 12:0 < 12:2023-05-0112:2023-05-01
platformframeworks_native>= 12L:0 < 12L:2023-05-0112L:2023-05-01
platformframeworks_native>= 13-next:0 < 13-next:2023-05-0113-next:2023-05-01
platformpackages_apps_packageinstaller>= 11:0 < 11:2023-05-0111:2023-05-01
platformpackages_modules_permission>= 12:0 < 12:2023-05-0112:2023-05-01
platformpackages_modules_permission>= 13-next:0 < 13-next:2023-05-0113-next:2023-05-01