In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution privileges needed. User interaction is needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"3187232592425814798170242992126179054",
"200689881885266226857086265806910835767",
"154729374020362673883941306015094027664",
"203051173170714291080127555135759847274",
"58063598350332370326758486265581278590",
"142251778555814498814410223942669123035",
"26443495149634102669487743541124431935"
]
},
"id": "ASB-A-155648639-4ef404c8",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407",
"target": {
"file": "src/com/android/settings/bluetooth/BluetoothPairingDialog.java"
}
},
{
"digest": {
"length": 751.0,
"function_hash": "49858146941061449718593128253940867238"
},
"id": "ASB-A-155648639-ce3f4742",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407",
"target": {
"function": "onCreate",
"file": "src/com/android/settings/bluetooth/BluetoothPairingDialog.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407"
],
"types": [
"EoP"
],
"spl": "2020-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"3187232592425814798170242992126179054",
"200689881885266226857086265806910835767",
"154729374020362673883941306015094027664",
"203051173170714291080127555135759847274",
"58063598350332370326758486265581278590",
"142251778555814498814410223942669123035",
"26443495149634102669487743541124431935"
]
},
"id": "ASB-A-155648639-41ef7c06",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407",
"target": {
"file": "src/com/android/settings/bluetooth/BluetoothPairingDialog.java"
}
},
{
"digest": {
"length": 751.0,
"function_hash": "49858146941061449718593128253940867238"
},
"id": "ASB-A-155648639-4aa15350",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407",
"target": {
"function": "onCreate",
"file": "src/com/android/settings/bluetooth/BluetoothPairingDialog.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407"
],
"types": [
"EoP"
],
"spl": "2020-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"3187232592425814798170242992126179054",
"200689881885266226857086265806910835767",
"154729374020362673883941306015094027664",
"203051173170714291080127555135759847274",
"58063598350332370326758486265581278590",
"142251778555814498814410223942669123035",
"26443495149634102669487743541124431935"
]
},
"id": "ASB-A-155648639-3d2af61f",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407",
"target": {
"file": "src/com/android/settings/bluetooth/BluetoothPairingDialog.java"
}
},
{
"digest": {
"length": 751.0,
"function_hash": "49858146941061449718593128253940867238"
},
"id": "ASB-A-155648639-73955f5f",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407",
"target": {
"function": "onCreate",
"file": "src/com/android/settings/bluetooth/BluetoothPairingDialog.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407"
],
"types": [
"EoP"
],
"spl": "2020-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"3187232592425814798170242992126179054",
"200689881885266226857086265806910835767",
"154729374020362673883941306015094027664",
"203051173170714291080127555135759847274",
"58063598350332370326758486265581278590",
"142251778555814498814410223942669123035",
"26443495149634102669487743541124431935"
]
},
"id": "ASB-A-155648639-499282d3",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407",
"target": {
"file": "src/com/android/settings/bluetooth/BluetoothPairingDialog.java"
}
},
{
"digest": {
"length": 751.0,
"function_hash": "49858146941061449718593128253940867238"
},
"id": "ASB-A-155648639-e94a79c8",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407",
"target": {
"function": "onCreate",
"file": "src/com/android/settings/bluetooth/BluetoothPairingDialog.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/f3afef8419de2910b03c3670ca25e63ac3c08407"
],
"types": [
"EoP"
],
"spl": "2020-09-01",
"severity": "High"
}