CVE-2021-39617UI Misrepresentation / Clickjacking in Frameworks Base

Severity
N/A
No vector
EPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1

Description

In multiple buttons of grant_permissions.xml, there is a possible way to bypass permissions dialogs due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Affected Packages4 packages

Androidplatform/frameworks_base11:011:2023-05-01+1
Androidplatform/frameworks_native13-next:013-next:2023-05-01+3
Androidplatform/packages_modules_permission13-next:013-next:2023-05-01+1
Androidplatform/packages_apps_packageinstaller11:011:2023-05-01

🔴Vulnerability Details

2
OSV
CVE-2021-39617: In multiple buttons of grant_permissions2023-05-01
GHSA
GHSA-jvp9-5xr3-p4jg: In the user interface buttons of PermissionController, there is a possible way to bypass permissions dialogs due to a tapjacking/overlay attack2022-12-13

📋Vendor Advisories

1
Android
CVE-2021-39617: Android Security Bulletin 2023-05-01 CVE: CVE-2021-39617 Severity: HIGH Type: EoP Affected AOSP versions: 11, 12, 12L References: A-1751908442023-05-01
CVE-2021-39617 — UI Misrepresentation / Clickjacking | cvebase