First published: Mon Dec 07 2020(Updated: )
In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-141745510
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Android | =8.0 | |
Android | =8.1 | |
Android | =9.0 | |
Android | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0099 is a vulnerability in the Android operating system that allows for a window overlay attack, potentially leading to local privilege escalation.
CVE-2020-0099 has a severity rating of 7.8 (High).
Versions 8.0, 8.1, 9.0, and 10.0 of Google Android are affected by CVE-2020-0099.
An attacker can exploit CVE-2020-0099 by utilizing a window overlay attack, such as tapjacking, to escalate their privileges.
To mitigate CVE-2020-0099, it is recommended to update your Android device to the latest version available from Google.