ASB-A-172322502

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-172322502.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-172322502
Aliases
Published
2021-04-01T00:00:00Z
Modified
2026-04-22T14:59:17.843400Z
Summary
[none]
Details

In start of WelcomeActivity.java, there is a possible residual profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android / platform/packages/apps/ManagedProvisioning

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9:0
Fixed
9:2021-04-05

Affected versions

Other
9

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "267192170493229523696223573646670273399",
                    "338038645278955396091962215389328351175",
                    "222592965601268419775985950103889431668",
                    "101324354763547935278631398959791876538",
                    "109139238108337384528376725384688091678",
                    "157370780375504858674881480152622921994",
                    "317330206669925724325579129324567481825",
                    "63426012201672372493438705069252786800",
                    "249171790815410219612734183124320482265",
                    "180404932187257232605504121047543543358",
                    "288690388350496034889718794049660130460"
                ]
            },
            "id": "ASB-A-172322502-6da0f4ec",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/packages/apps/ManagedProvisioning/+/e2e7db03f6629a049d7f9a255b1238182b104435",
            "target": {
                "file": "src/com/android/managedprovisioning/finalization/FinalizationController.java"
            }
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "228725422874890500404722894961141832503",
                    "141934198722136723954338757764907351491",
                    "218227820810902030954871776798730062028",
                    "225565816507896717753283047892474050207",
                    "112738795450441930932611522079018513168",
                    "114071533140300265248204588839640086702",
                    "20589838921031885125274903363280850225",
                    "261988694032451924320424717076509552746",
                    "244178575112175948922872806110849256185"
                ]
            },
            "id": "ASB-A-172322502-f770adf0",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/packages/apps/ManagedProvisioning/+/e2e7db03f6629a049d7f9a255b1238182b104435",
            "target": {
                "file": "src/com/android/managedprovisioning/finalization/FinalizationActivity.java"
            }
        },
        {
            "digest": {
                "length": 117.0,
                "function_hash": "113269246220345807028762452177490341681"
            },
            "id": "ASB-A-172322502-fac1a50b",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/packages/apps/ManagedProvisioning/+/e2e7db03f6629a049d7f9a255b1238182b104435",
            "target": {
                "function": "onCreate",
                "file": "src/com/android/managedprovisioning/finalization/FinalizationActivity.java"
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/packages/apps/ManagedProvisioning/+/e2e7db03f6629a049d7f9a255b1238182b104435"
    ],
    "types": [
        "EoP"
    ],
    "spl": "2021-04-05",
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-172322502.json"