CVE-2019-2043: High severity Google Android vulnerability
In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay attack. This could lead to local escalation of privilege, granting privileges to a local app without the user's informed consent, with no additional privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-120484087
Affected Software
Event History
Frequently Asked Questions
Which Android releases are affected?
The issue affects Android 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.
What does an attacker need to exploit this issue?
An attacker needs a local app on the device and user interaction. The flaw uses an overlay attack to obtain privileges without the user's informed consent, and no additional attacker privileges are required.
What is the potential impact?
Successful exploitation can result in local privilege escalation, with high impact to confidentiality, integrity, and availability.