In createPendingIntent of SnoozeHelper.java, there is a possible broadcast intent containing a sensitive identifier. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
{
"types": [
"ID"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/1433925beb00b7c8b9909a8c7c6a9cf559ac9b8e"
],
"spl": "2021-05-01",
"vanir_signatures": [
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 409.0,
"function_hash": "339865205078367648010671210766896011404"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/1433925beb00b7c8b9909a8c7c6a9cf559ac9b8e",
"id": "ASB-A-174493336-0e43a7a7",
"target": {
"function": "createPendingIntent",
"file": "services/core/java/com/android/server/notification/SnoozeHelper.java"
},
"signature_type": "Function"
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"57118115860121071837854322048167688985",
"47238616169572522949335276847548604161",
"154646965573311299005471263044801222397",
"124366016068665535373153331052570312854"
]
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/1433925beb00b7c8b9909a8c7c6a9cf559ac9b8e",
"id": "ASB-A-174493336-b6e68774",
"signature_type": "Line",
"target": {
"file": "services/core/java/com/android/server/notification/SnoozeHelper.java"
}
}
],
"severity": "High"
}
{
"types": [
"ID"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/b341523840ed04c01542e476da71c02d1dd5fa8d"
],
"spl": "2021-05-01",
"vanir_signatures": [
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"57118115860121071837854322048167688985",
"47238616169572522949335276847548604161",
"154646965573311299005471263044801222397",
"124366016068665535373153331052570312854"
]
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/b341523840ed04c01542e476da71c02d1dd5fa8d",
"id": "ASB-A-174493336-4765c889",
"signature_type": "Line",
"target": {
"file": "services/core/java/com/android/server/notification/SnoozeHelper.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 409.0,
"function_hash": "339865205078367648010671210766896011404"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/b341523840ed04c01542e476da71c02d1dd5fa8d",
"id": "ASB-A-174493336-7f54c561",
"target": {
"function": "createPendingIntent",
"file": "services/core/java/com/android/server/notification/SnoozeHelper.java"
},
"signature_type": "Function"
}
],
"severity": "High"
}
{
"types": [
"ID"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/49688ab6597106f5d0ae0466327945ba34970001"
],
"spl": "2021-05-01",
"vanir_signatures": [
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"317920005138416377052735521750357248666",
"157401339543306613815959896872676267209",
"190292671684033020619939668019540309235",
"1093300827834225668349198205565276794",
"57118115860121071837854322048167688985",
"47238616169572522949335276847548604161",
"154646965573311299005471263044801222397",
"124366016068665535373153331052570312854"
]
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/49688ab6597106f5d0ae0466327945ba34970001",
"id": "ASB-A-174493336-81a4a696",
"signature_type": "Line",
"target": {
"file": "services/core/java/com/android/server/notification/SnoozeHelper.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 409.0,
"function_hash": "339865205078367648010671210766896011404"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/49688ab6597106f5d0ae0466327945ba34970001",
"id": "ASB-A-174493336-9def0178",
"signature_type": "Function",
"target": {
"function": "createPendingIntent",
"file": "services/core/java/com/android/server/notification/SnoozeHelper.java"
}
}
],
"severity": "High"
}
{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/c73916229dda8ebef766cd40e04bbc63059ee3e5"
],
"spl": "2021-05-01",
"types": [
"ID"
],
"vanir_signatures": [
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"257749157829183524376598762715384610232",
"139008779563235058325452161350667823207",
"65308961381566962030056746362125913845",
"152508573877629842257368087625699243358",
"57118115860121071837854322048167688985",
"47238616169572522949335276847548604161",
"154646965573311299005471263044801222397",
"124366016068665535373153331052570312854"
]
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/c73916229dda8ebef766cd40e04bbc63059ee3e5",
"id": "ASB-A-174493336-28c1548d",
"signature_type": "Line",
"target": {
"file": "services/core/java/com/android/server/notification/SnoozeHelper.java"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 409.0,
"function_hash": "339865205078367648010671210766896011404"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/c73916229dda8ebef766cd40e04bbc63059ee3e5",
"id": "ASB-A-174493336-d98da04d",
"signature_type": "Function",
"target": {
"file": "services/core/java/com/android/server/notification/SnoozeHelper.java",
"function": "createPendingIntent"
}
}
]
}