Typical severity: High. Likelihood of attack: Medium. An adversary, through a previously installed malicious application, impersonates a credential prompt in an attempt to steal a user's credentials.
The only known mitigation to this attack is to avoid installing the malicious application on the device. However, to impersonate a running task the malicious application does need the GET_TASKS permission to be able to query the task list, and being suspicious of applications with that permission can help.