In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass background activity launch restrictions via a pendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/f4cedb277354040228a785776a5b017d64baf1f5", "https://android.googlesource.com/platform/frameworks/base/+/f1f080fd362d03a5996290fb91155522b5d44914" ], "spl": "2023-04-01", "types": [ "EoP" ], "severity": "Moderate" }