In notification access permission dialog box, malicious application can embedded a very long service label that overflow the original user prompt and possibly contains mis-leading information to be appeared as a system message for user confirmation.
The product does not properly verify that the source of data or communication is valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Android | 10.0 (including) | 10.0 (including) | |
| Android | 11.0 (including) | 11.0 (including) | |
| Android | 12.1 (including) | 12.1 (including) | |
| Android | 13.0 (including) | 13.0 (including) |