Vulnerabilities > CVE-2022-20214 - Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0/11.0/12.0

047910
CVSS 4.7 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
google
CWE-1021

Summary

In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183411210

Vulnerable Configurations

Part Description Count
OS
Google
3