In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"length": 3142.0,
"function_hash": "197900126845587824394117090079378270627"
},
"id": "ASB-A-156021269-6de86636",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff",
"target": {
"function": "setNotification",
"file": "src/com/android/bluetooth/sap/SapServer.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"144029841568908408176958828052010481441",
"305624968972022862758798491584251603702",
"147220089984050424096213671662241802959",
"282390294194296649121608924362399303020"
]
},
"id": "ASB-A-156021269-b5211175",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff",
"target": {
"file": "src/com/android/bluetooth/sap/SapServer.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff"
],
"types": [
"ID"
],
"spl": "2020-10-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"144029841568908408176958828052010481441",
"305624968972022862758798491584251603702",
"147220089984050424096213671662241802959",
"282390294194296649121608924362399303020"
]
},
"id": "ASB-A-156021269-1a6f915a",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff",
"target": {
"file": "src/com/android/bluetooth/sap/SapServer.java"
}
},
{
"digest": {
"length": 3142.0,
"function_hash": "197900126845587824394117090079378270627"
},
"id": "ASB-A-156021269-9b7bb242",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff",
"target": {
"function": "setNotification",
"file": "src/com/android/bluetooth/sap/SapServer.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff"
],
"types": [
"ID"
],
"spl": "2020-10-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 3142.0,
"function_hash": "197900126845587824394117090079378270627"
},
"id": "ASB-A-156021269-5fdc5d07",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff",
"target": {
"function": "setNotification",
"file": "src/com/android/bluetooth/sap/SapServer.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"144029841568908408176958828052010481441",
"305624968972022862758798491584251603702",
"147220089984050424096213671662241802959",
"282390294194296649121608924362399303020"
]
},
"id": "ASB-A-156021269-c1a30efb",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff",
"target": {
"file": "src/com/android/bluetooth/sap/SapServer.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff"
],
"types": [
"ID"
],
"spl": "2020-10-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"144029841568908408176958828052010481441",
"305624968972022862758798491584251603702",
"147220089984050424096213671662241802959",
"282390294194296649121608924362399303020"
]
},
"id": "ASB-A-156021269-54726431",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff",
"target": {
"file": "src/com/android/bluetooth/sap/SapServer.java"
}
},
{
"digest": {
"length": 3142.0,
"function_hash": "197900126845587824394117090079378270627"
},
"id": "ASB-A-156021269-91753870",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff",
"target": {
"function": "setNotification",
"file": "src/com/android/bluetooth/sap/SapServer.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff"
],
"types": [
"ID"
],
"spl": "2020-10-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"144029841568908408176958828052010481441",
"305624968972022862758798491584251603702",
"147220089984050424096213671662241802959",
"282390294194296649121608924362399303020"
]
},
"id": "ASB-A-156021269-2ec092f2",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff",
"target": {
"file": "src/com/android/bluetooth/sap/SapServer.java"
}
},
{
"digest": {
"length": 3142.0,
"function_hash": "197900126845587824394117090079378270627"
},
"id": "ASB-A-156021269-5e27e971",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff",
"target": {
"function": "setNotification",
"file": "src/com/android/bluetooth/sap/SapServer.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Bluetooth/+/4e9aefd2167cffd745d92abe4c7ce3b2bdbd91ff"
],
"types": [
"ID"
],
"spl": "2020-10-01",
"severity": "High"
}