CVE-2021-0954
HIGHAndroid - Tapjacking/Overlay Attack in ResolverActivity
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-0954. PoCs published by nanopathi.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2021-0954, targeting Android's Autofill framework. The provided test cases demonstrate the vulnerability by manipulating focus events and autofill responses, potentially leading to privilege escalation or unauthorized data access.
Description
In ResolverActivity, there is a possible user interaction bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-143559931
Exploits (1)
This repository contains functional exploit code for CVE-2021-0954, targeting Android's Autofill framework. The provided test cases demonstrate the vulnerability by manipulating focus events and autofill responses, potentially leading to privilege escalation or unauthorized data access.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H