First published: Mon Aug 05 2019(Updated: )
An application with overlay permission can display overlays on top of settings UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-119115683.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =7.0 | |
Android | =7.1.1 | |
Android | =7.1.2 | |
Android | =8.0 | |
Android | =8.1 | |
Android | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2131 is classified as a high severity vulnerability due to its potential for local escalation of privilege.
To fix CVE-2019-2131, update your Android device to the latest security patch provided by Google.
CVE-2019-2131 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
Yes, user interaction is required for the exploitation of CVE-2019-2131.
CVE-2019-2131 can allow an application with overlay permission to display overlays on top of the settings UI, which may compromise user privacy.