PT-2022-14734 · Google · Android

Published

2022-12-16

·

Updated

2022-12-20

·

CVE-2022-20520

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-13
Description The issue is related to a possible tapjacking/overlay attack in the onCreate of various files. This could lead to local escalation of privilege or denial of server with User execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android version Android-13, consider implementing additional security measures to prevent tapjacking/overlay attacks, such as validating the origin of user input or restricting access to sensitive functionality. As a temporary workaround, consider disabling or restricting the use of the vulnerable onCreate method in affected files until a patch is available.

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2022-20520

Affected Products

Android