Vulnerabilities > CVE-2022-33723 - Improper Restriction of Rendered UI Layers or Frames vulnerability in Google Android 10.0/11.0/12.0

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
google
CWE-1021

Summary

A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

Vulnerable Configurations

Part Description Count
OS
Google
3