In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 1126.0, "function_hash": "156274068117707442826839663595663247076" }, "id": "ASB-A-205595291-1df34339", "source": "https://android.googlesource.com/platform/frameworks/base/+/53ee9c2472ddba0974e0b6b5dc33dbad67509199", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "230270167553595103007514570852627461596", "297950520457323012590384082127709064872", "121517790874538438440243064707270506900", "98378032701324203129075527163256888487", "42344667029625858263766566166371255759", "292289074368362542279077340109773786528", "291032462713778241914747717841294520177", "220695610766102913280912325197082737925" ] }, "id": "ASB-A-205595291-423fdeed", "source": "https://android.googlesource.com/platform/frameworks/base/+/53ee9c2472ddba0974e0b6b5dc33dbad67509199", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/53ee9c2472ddba0974e0b6b5dc33dbad67509199" ], "spl": "2022-04-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 1126.0, "function_hash": "156274068117707442826839663595663247076" }, "id": "ASB-A-205595291-3aa04d3b", "source": "https://android.googlesource.com/platform/frameworks/base/+/2c87a8a7cec276a9e4cf88e0ae410fd43ffb0b38", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "230270167553595103007514570852627461596", "297950520457323012590384082127709064872", "121517790874538438440243064707270506900", "98378032701324203129075527163256888487", "42344667029625858263766566166371255759", "292289074368362542279077340109773786528", "291032462713778241914747717841294520177", "220695610766102913280912325197082737925" ] }, "id": "ASB-A-205595291-d2163bac", "source": "https://android.googlesource.com/platform/frameworks/base/+/2c87a8a7cec276a9e4cf88e0ae410fd43ffb0b38", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/2c87a8a7cec276a9e4cf88e0ae410fd43ffb0b38" ], "spl": "2022-04-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 1126.0, "function_hash": "156274068117707442826839663595663247076" }, "id": "ASB-A-205595291-0e249f26", "source": "https://android.googlesource.com/platform/frameworks/base/+/9c5c42ad035a493d68669628ed7ac21e6fbed7f9", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "230270167553595103007514570852627461596", "297950520457323012590384082127709064872", "121517790874538438440243064707270506900", "98378032701324203129075527163256888487", "42344667029625858263766566166371255759", "292289074368362542279077340109773786528", "291032462713778241914747717841294520177", "220695610766102913280912325197082737925" ] }, "id": "ASB-A-205595291-53a7b3e7", "source": "https://android.googlesource.com/platform/frameworks/base/+/9c5c42ad035a493d68669628ed7ac21e6fbed7f9", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/9c5c42ad035a493d68669628ed7ac21e6fbed7f9" ], "spl": "2022-04-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "230270167553595103007514570852627461596", "297950520457323012590384082127709064872", "121517790874538438440243064707270506900", "98378032701324203129075527163256888487", "42344667029625858263766566166371255759", "292289074368362542279077340109773786528", "291032462713778241914747717841294520177", "220695610766102913280912325197082737925" ] }, "id": "ASB-A-205595291-0377fbf8", "source": "https://android.googlesource.com/platform/frameworks/base/+/f36b7b9f80fde732aa102b04cd8ce6a6db1a3616", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java" }, "signature_type": "Line" }, { "digest": { "length": 1126.0, "function_hash": "156274068117707442826839663595663247076" }, "id": "ASB-A-205595291-1b3d2abb", "source": "https://android.googlesource.com/platform/frameworks/base/+/f36b7b9f80fde732aa102b04cd8ce6a6db1a3616", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java", "function": "onCreate" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/f36b7b9f80fde732aa102b04cd8ce6a6db1a3616" ], "spl": "2022-04-01", "severity": "High", "types": [ "EoP" ] }