← back
CVE-2022-20214

CVE-2022-20214

CVSS 4.7 MEDIUMEPSS 0.2%CWE-1021
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.7EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
24 Jan 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle button to enable apps to modify system settings without user consent.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-183411210
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Affected products
n/a · Android

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →