{"id":"ASB-A-174047492","details":"In onCreate of WifiScanModeActivity.java, there is a possible way to enable Wi-Fi scanning without user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.","aliases":["A-174047492","CVE-2021-0523"],"modified":"2026-05-26T15:46:26.044149249Z","published":"2021-06-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2021-06-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/apps/Settings/+/05d6fa9bcb90886ac2611f86bb7d2af7078eb3ad"}],"affected":[{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2021-06-01"}]}],"versions":["10"],"ecosystem_specific":{"types":["EoP"],"severity":"High","vanir_signatures":[{"signature_type":"Line","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/faa5f6b5f6b67421f1327690f358f2fc5ee12c33","signature_version":"v1","id":"ASB-A-174047492-2bfb51b8","digest":{"threshold":0.9,"line_hashes":["328263169580508867976876575400628265794","110424566519442481665465581655237687646","322102221475400443108148106970967004392","108217010661045898630435102137187521905","295920884582073271744377298668040679510","287274780326124899620192979046656855227","185974074193300355660243960888347440480","92475357582801666664465760516120286434"]},"deprecated":false,"target":{"file":"src/com/android/settings/wifi/WifiScanModeActivity.java"}},{"source":"https://android.googlesource.com/platform/packages/apps/Settings/+/faa5f6b5f6b67421f1327690f358f2fc5ee12c33","signature_type":"Function","signature_version":"v1","id":"ASB-A-174047492-8bf326c4","digest":{"length":512,"function_hash":"216698803617722576029150201810114412891"},"target":{"file":"src/com/android/settings/wifi/WifiScanModeActivity.java","function":"onCreate"},"deprecated":false}],"spl":"2021-06-01","fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/faa5f6b5f6b67421f1327690f358f2fc5ee12c33"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-174047492.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2021-06-01"}]}],"versions":["11"],"ecosystem_specific":{"types":["EoP"],"severity":"High","vanir_signatures":[{"source":"https://android.googlesource.com/platform/packages/apps/Settings/+/58b0f2d5b3ab4e7002b870aedc971a2d8d9e8e44","signature_type":"Function","signature_version":"v1","id":"ASB-A-174047492-567d4985","digest":{"length":512,"function_hash":"158803676454670411362006961934677279220"},"deprecated":false,"target":{"file":"src/com/android/settings/wifi/WifiScanModeActivity.java","function":"onCreate"}},{"signature_type":"Line","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/58b0f2d5b3ab4e7002b870aedc971a2d8d9e8e44","signature_version":"v1","id":"ASB-A-174047492-8c8fe44a","digest":{"threshold":0.9,"line_hashes":["278439482067112957380265895062969078593","62494506271113635611819801336893045692","202940160376952609789420844645356167769","108217010661045898630435102137187521905","295920884582073271744377298668040679510","287274780326124899620192979046656855227","185974074193300355660243960888347440480","326699467371759243067822480658829003894"]},"deprecated":false,"target":{"file":"src/com/android/settings/wifi/WifiScanModeActivity.java"}}],"spl":"2021-06-01","fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/58b0f2d5b3ab4e7002b870aedc971a2d8d9e8e44"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-174047492.json"}}],"schema_version":"1.7.5"}