In ActivityPicker.java, there is a possible bypass of user interaction in intent resolution due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 916.0, "function_hash": "205185686415413105272215436771915477739" }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/8a9fafb37d089789b2017676942da2da001ac47d", "target": { "file": "src/com/android/settings/ActivityPicker.java", "function": "onCreate" }, "id": "ASB-A-181962311-387bd507", "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "13917053636421386471929265823444253584", "80829123100825695380556064374738997322", "292289074368362542279077340109773786528", "185945154138790307882385540569992421939", "234118073180999875281221007551057574324" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/8a9fafb37d089789b2017676942da2da001ac47d", "target": { "file": "src/com/android/settings/ActivityPicker.java" }, "id": "ASB-A-181962311-7f7b39d6", "signature_type": "Line" } ], "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/8a9fafb37d089789b2017676942da2da001ac47d" ], "spl": "2021-06-01" }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "13917053636421386471929265823444253584", "80829123100825695380556064374738997322", "292289074368362542279077340109773786528", "185945154138790307882385540569992421939", "234118073180999875281221007551057574324" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/636e70fbf2b9ef789e96add206fd7fcc816f61b6", "target": { "file": "src/com/android/settings/ActivityPicker.java" }, "id": "ASB-A-181962311-51b95827", "signature_type": "Line" }, { "digest": { "length": 916.0, "function_hash": "205185686415413105272215436771915477739" }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/636e70fbf2b9ef789e96add206fd7fcc816f61b6", "target": { "file": "src/com/android/settings/ActivityPicker.java", "function": "onCreate" }, "id": "ASB-A-181962311-5b6a6766", "signature_type": "Function" } ], "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/636e70fbf2b9ef789e96add206fd7fcc816f61b6" ], "spl": "2021-06-01" }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "13917053636421386471929265823444253584", "80829123100825695380556064374738997322", "292289074368362542279077340109773786528", "185945154138790307882385540569992421939", "234118073180999875281221007551057574324" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/eac0ba87d0bfc700ab2e565ff673175f460147c6", "target": { "file": "src/com/android/settings/ActivityPicker.java" }, "id": "ASB-A-181962311-11181a47", "signature_type": "Line" }, { "digest": { "length": 916.0, "function_hash": "205185686415413105272215436771915477739" }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/eac0ba87d0bfc700ab2e565ff673175f460147c6", "target": { "file": "src/com/android/settings/ActivityPicker.java", "function": "onCreate" }, "id": "ASB-A-181962311-a8d34e6b", "signature_type": "Function" } ], "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/eac0ba87d0bfc700ab2e565ff673175f460147c6" ], "spl": "2021-06-01" }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "13917053636421386471929265823444253584", "80829123100825695380556064374738997322", "292289074368362542279077340109773786528", "185945154138790307882385540569992421939", "234118073180999875281221007551057574324" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2445ba01cd194a07a79b93ee45e2e9fff35ca9a7", "target": { "file": "src/com/android/settings/ActivityPicker.java" }, "id": "ASB-A-181962311-041dc308", "signature_type": "Line" }, { "digest": { "length": 916.0, "function_hash": "205185686415413105272215436771915477739" }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2445ba01cd194a07a79b93ee45e2e9fff35ca9a7", "target": { "file": "src/com/android/settings/ActivityPicker.java", "function": "onCreate" }, "id": "ASB-A-181962311-eebc833e", "signature_type": "Function" } ], "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/2445ba01cd194a07a79b93ee45e2e9fff35ca9a7" ], "spl": "2021-06-01" }