In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
{
"types": [
"EoP"
],
"spl": "2022-04-01",
"severity": "High",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/53ee9c2472ddba0974e0b6b5dc33dbad67509199",
"target": {
"function": "onCreate",
"file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "156274068117707442826839663595663247076",
"length": 1126.0
},
"id": "ASB-A-205595291-1df34339",
"signature_version": "v1"
},
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/53ee9c2472ddba0974e0b6b5dc33dbad67509199",
"target": {
"file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"230270167553595103007514570852627461596",
"297950520457323012590384082127709064872",
"121517790874538438440243064707270506900",
"98378032701324203129075527163256888487",
"42344667029625858263766566166371255759",
"292289074368362542279077340109773786528",
"291032462713778241914747717841294520177",
"220695610766102913280912325197082737925"
],
"threshold": 0.9
},
"id": "ASB-A-205595291-423fdeed",
"signature_version": "v1"
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/53ee9c2472ddba0974e0b6b5dc33dbad67509199"
]
}
{
"types": [
"EoP"
],
"spl": "2022-04-01",
"severity": "High",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/2c87a8a7cec276a9e4cf88e0ae410fd43ffb0b38",
"target": {
"function": "onCreate",
"file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "156274068117707442826839663595663247076",
"length": 1126.0
},
"id": "ASB-A-205595291-3aa04d3b",
"signature_version": "v1"
},
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/2c87a8a7cec276a9e4cf88e0ae410fd43ffb0b38",
"target": {
"file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"230270167553595103007514570852627461596",
"297950520457323012590384082127709064872",
"121517790874538438440243064707270506900",
"98378032701324203129075527163256888487",
"42344667029625858263766566166371255759",
"292289074368362542279077340109773786528",
"291032462713778241914747717841294520177",
"220695610766102913280912325197082737925"
],
"threshold": 0.9
},
"id": "ASB-A-205595291-d2163bac",
"signature_version": "v1"
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/2c87a8a7cec276a9e4cf88e0ae410fd43ffb0b38"
]
}
{
"types": [
"EoP"
],
"spl": "2022-04-01",
"severity": "High",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/9c5c42ad035a493d68669628ed7ac21e6fbed7f9",
"target": {
"function": "onCreate",
"file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "156274068117707442826839663595663247076",
"length": 1126.0
},
"id": "ASB-A-205595291-0e249f26",
"signature_version": "v1"
},
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/9c5c42ad035a493d68669628ed7ac21e6fbed7f9",
"target": {
"file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"230270167553595103007514570852627461596",
"297950520457323012590384082127709064872",
"121517790874538438440243064707270506900",
"98378032701324203129075527163256888487",
"42344667029625858263766566166371255759",
"292289074368362542279077340109773786528",
"291032462713778241914747717841294520177",
"220695610766102913280912325197082737925"
],
"threshold": 0.9
},
"id": "ASB-A-205595291-53a7b3e7",
"signature_version": "v1"
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/9c5c42ad035a493d68669628ed7ac21e6fbed7f9"
]
}
{
"types": [
"EoP"
],
"spl": "2022-04-01",
"severity": "High",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/f36b7b9f80fde732aa102b04cd8ce6a6db1a3616",
"target": {
"file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"230270167553595103007514570852627461596",
"297950520457323012590384082127709064872",
"121517790874538438440243064707270506900",
"98378032701324203129075527163256888487",
"42344667029625858263766566166371255759",
"292289074368362542279077340109773786528",
"291032462713778241914747717841294520177",
"220695610766102913280912325197082737925"
],
"threshold": 0.9
},
"id": "ASB-A-205595291-0377fbf8",
"signature_version": "v1"
},
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/f36b7b9f80fde732aa102b04cd8ce6a6db1a3616",
"target": {
"function": "onCreate",
"file": "core/java/com/android/internal/app/HarmfulAppWarningActivity.java"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "156274068117707442826839663595663247076",
"length": 1126.0
},
"id": "ASB-A-205595291-1b3d2abb",
"signature_version": "v1"
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/f36b7b9f80fde732aa102b04cd8ce6a6db1a3616"
]
}