In readFrom of Uri.java, there is a possible bad URI permission grant due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"deprecated": false,
"digest": {
"line_hashes": [
"217293375901536488373202122972823323969",
"64913045587930263071620006027114995635",
"133802527225369483754931688542697427099",
"160009536855085451358753916392621805401",
"108665550764986394327745700644898793881",
"238342223150607425782371454756028319372",
"285677272714058008081533384476939390622",
"213183156118135730613894113137757047267",
"191618998247855941167627426111353121754",
"229221336185881681659960120095347110956",
"214877076543316569988414134525175557655",
"300917551157252855785981741901753753877",
"62817408602554622937841706145635928073"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/f37a94ae920fa5879c557603fc285942ec4b84b1",
"id": "ASB-A-227471459-9057e044",
"target": {
"file": "core/java/android/net/Uri.java"
}
},
{
"deprecated": false,
"digest": {
"length": 197.0,
"function_hash": "40263653748956335830809431209081902639"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/f37a94ae920fa5879c557603fc285942ec4b84b1",
"id": "ASB-A-227471459-e47c4ece",
"target": {
"function": "readFrom",
"file": "core/java/android/net/Uri.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/f37a94ae920fa5879c557603fc285942ec4b84b1"
],
"spl": "2023-08-01",
"severity": "High",
"types": [
"EoP"
]
}
{
"vanir_signatures": [
{
"deprecated": false,
"digest": {
"line_hashes": [
"217293375901536488373202122972823323969",
"64913045587930263071620006027114995635",
"133802527225369483754931688542697427099",
"160009536855085451358753916392621805401",
"108665550764986394327745700644898793881",
"238342223150607425782371454756028319372",
"285677272714058008081533384476939390622",
"213183156118135730613894113137757047267",
"191618998247855941167627426111353121754",
"229221336185881681659960120095347110956",
"214877076543316569988414134525175557655",
"119157369104391389495237517514297622080",
"210632989439468116936103427892354174345"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/c87f0623be4042c39a9b73f7a6e02aa116925e50",
"id": "ASB-A-227471459-8faec97e",
"target": {
"file": "core/java/android/net/Uri.java"
}
},
{
"deprecated": false,
"digest": {
"length": 197.0,
"function_hash": "40263653748956335830809431209081902639"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/c87f0623be4042c39a9b73f7a6e02aa116925e50",
"id": "ASB-A-227471459-b680b350",
"target": {
"function": "readFrom",
"file": "core/java/android/net/Uri.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/c87f0623be4042c39a9b73f7a6e02aa116925e50"
],
"spl": "2023-08-01",
"severity": "High",
"types": [
"EoP"
]
}
{
"vanir_signatures": [
{
"deprecated": false,
"digest": {
"length": 197.0,
"function_hash": "40263653748956335830809431209081902639"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/d83281c73070f2428754912ede95ecb0e3d69cd5",
"id": "ASB-A-227471459-650176e1",
"target": {
"function": "readFrom",
"file": "core/java/android/net/Uri.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"217293375901536488373202122972823323969",
"64913045587930263071620006027114995635",
"133802527225369483754931688542697427099",
"160009536855085451358753916392621805401",
"108665550764986394327745700644898793881",
"238342223150607425782371454756028319372",
"285677272714058008081533384476939390622",
"213183156118135730613894113137757047267",
"191618998247855941167627426111353121754",
"229221336185881681659960120095347110956",
"214877076543316569988414134525175557655",
"300917551157252855785981741901753753877",
"62817408602554622937841706145635928073"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/d83281c73070f2428754912ede95ecb0e3d69cd5",
"id": "ASB-A-227471459-e4869c7c",
"target": {
"file": "core/java/android/net/Uri.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/d83281c73070f2428754912ede95ecb0e3d69cd5"
],
"spl": "2023-08-01",
"severity": "High",
"types": [
"EoP"
]
}
{
"vanir_signatures": [
{
"deprecated": false,
"digest": {
"length": 197.0,
"function_hash": "40263653748956335830809431209081902639"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/dcc1fb8e8be12324e1a8277023955d9f92cd5626",
"id": "ASB-A-227471459-9c48c1b9",
"target": {
"function": "readFrom",
"file": "core/java/android/net/Uri.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"217293375901536488373202122972823323969",
"64913045587930263071620006027114995635",
"133802527225369483754931688542697427099",
"160009536855085451358753916392621805401",
"108665550764986394327745700644898793881",
"238342223150607425782371454756028319372",
"285677272714058008081533384476939390622",
"213183156118135730613894113137757047267",
"191618998247855941167627426111353121754",
"229221336185881681659960120095347110956",
"214877076543316569988414134525175557655",
"300917551157252855785981741901753753877",
"62817408602554622937841706145635928073"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/dcc1fb8e8be12324e1a8277023955d9f92cd5626",
"id": "ASB-A-227471459-cf0e9b9e",
"target": {
"file": "core/java/android/net/Uri.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/dcc1fb8e8be12324e1a8277023955d9f92cd5626"
],
"spl": "2023-08-01",
"severity": "High",
"types": [
"EoP"
]
}