Android Tapjack Attack Vulnerability in WindowManagerService Allowing Local Privilege Escalation

Vulnerability

A vulnerability has been identified in the relayoutWindow function of WindowManagerService.java, where a missing permission check creates a potential tapjack attack. This flaw could lead to local privilege escalation without requiring additional execution privileges or user interaction.

Impact

Exploitation of this vulnerability could result in unauthorized privilege escalation.

Added: Mar 2, 2026, 7:41 PM
Updated: Mar 2, 2026, 9:02 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.