“For example, the app can request a permission that the user must approve, but cover that request notification with another screen that asks for something innocent, leaving a hole in the cover screen for the real βAcceptβ button. This type of bait and switch is a version of an attack known as βclick-jacking”
Yikes