In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation.
The product does not properly verify that the source of data or communication is valid.
Link | Tags |
---|---|
https://source.android.com/security/bulletin/aaos/2023-07-01 | vendor advisory |