PT-2022-21840 · Unknown · Bluetoothscandialog

Published

2022-08-05

·

Updated

2022-08-12

·

CVE-2022-33723

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BluetoothScanDialog versions prior to SMR Aug-2022 Release 1
Description A vulnerable code in the onCreate method of BluetoothScanDialog allows attackers to trick the user into selecting an unwanted Bluetooth device via tapjacking/overlay attack.
Recommendations For versions prior to SMR Aug-2022 Release 1, update to SMR Aug-2022 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the BluetoothScanDialog to minimize the risk of exploitation.

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2022-33723

Affected Products

Bluetoothscandialog