Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In NotificationAccessActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-182808318
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Google Android 访问控制错误漏洞
Vulnerability Description
Google Android是美国谷歌(Google)公司的的一套以Linux为基础的开源操作系统。 Google Android 存在访问控制错误漏洞,该漏洞源于在AndroidManifest.xml 的NotificationAccessActivity 中,由于tapjacking/overlay 攻击,可能存在EoP。 这可能会导致本地权限提升,而无需额外的执行权限。
CVSS Information
N/A
Vulnerability Type
N/A