Everybody without Android Oreo vulnerable to overlay attack
https://www.theregister.co.uk/2017/09/11/everybody_without_android_oreo_vulnerable_to_overlay_attack/
Any unpatched Android phone running a version older than Oreo is going to need patching fairly soon, with researchers turning up a class of vulnerability that lets malware draw fake dialogs so users “okay” their own pwnage.
The risk, according to Palo Alto Networks' researchers, comes from what's known as an overlay attack.