PT-2022-21844 · Unknown · Secdevicepickerdialog

Dzmitry Lukyanenka

·

Published

2022-08-05

·

Updated

2022-08-12

·

CVE-2022-33727

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SecDevicePickerDialog versions prior to SMR Aug-2022 Release 1
Description A vulnerable code in the onCreate method of SecDevicePickerDialog allows attackers to trick the user into selecting an unwanted Bluetooth device via tapjacking or overlay attack.
Recommendations For versions prior to SMR Aug-2022 Release 1, update to SMR Aug-2022 Release 1 or later to resolve the issue. As a temporary workaround, consider restricting the use of Bluetooth device selection features in SecDevicePickerDialog until a patch is available.

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2022-33727

Affected Products

Secdevicepickerdialog