PT-2022-10983 · Google · Android
Published
2022-03-01
·
Updated
2022-03-23
·
CVE-2021-39702
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions Android-12
Description
The issue is related to a tapjacking/overlay attack in the
onCreate method of RequestManageCredentials.java, allowing a third-party app to install certificates without user approval. This could lead to local escalation of privilege, requiring User execution privileges and user interaction for exploitation.Recommendations
For Android version Android-12, consider restricting access to the
RequestManageCredentials.java module to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the onCreate method of RequestManageCredentials.java until the issue is resolved.Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android