PT-2023-12638 · Google · Android

Published

2023-01-24

·

Updated

2025-04-01

·

CVE-2022-20214

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Android versions 10 through 12
Description The issue concerns a tapjacking attack vulnerability in the In Car Settings app, specifically with the toggle button in Modify system settings. This allows attackers to overlay the toggle button, enabling apps to modify system settings without user consent.
Recommendations For Android versions 10 through 12, consider disabling the Modify system settings toggle button in the In Car Settings app as a temporary workaround until a patch is available. Restrict access to system settings modifications to minimize the risk of exploitation.

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2022-20214

Affected Products

Android