Back

MEDIUM

In verifyInputEvent of InputDispatcher.cpp, there is a possible way to conduct click fraud due to side channel information disclosure

Published Jun 28, 2023

Description

In verifyInputEvent of InputDispatcher.cpp, there is a possible way to conduct click fraud due to side channel information disclosure. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-261085213

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner google_android
Published Jun 28, 2023
Updated Dec 4, 2024
Reserved Nov 3, 2022

CISA Vulnrichment

Updated Dec 4, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner google_android
Published Jun 28, 2023
Updated Dec 4, 2024

GitHub

No data