PT-2023-12638 · Google · Android
Published
2023-01-24
·
Updated
2025-04-01
·
CVE-2022-20214
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions 10 through 12
Description
The issue concerns a tapjacking attack vulnerability in the In Car Settings app, specifically with the toggle button in Modify system settings. This allows attackers to overlay the toggle button, enabling apps to modify system settings without user consent.
Recommendations
For Android versions 10 through 12, consider disabling the Modify system settings toggle button in the In Car Settings app as a temporary workaround until a patch is available. Restrict access to system settings modifications to minimize the risk of exploitation.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android