In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"severity": "High",
"spl": "2022-11-01",
"vanir_signatures": [
{
"signature_type": "Function",
"digest": {
"length": 1165.0,
"function_hash": "294971560677991495915799033849809071282"
},
"id": "ASB-A-240138318-44ad39a0",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/d2f9cc6342141cdb39f08a229d548d7b29cadd86",
"target": {
"file": "core/java/android/os/BaseBundle.java",
"function": "readFromParcelInner"
}
},
{
"signature_type": "Function",
"digest": {
"length": 1322.0,
"function_hash": "41618496558948515551579002358314189668"
},
"id": "ASB-A-240138318-95c0bcd0",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/d2f9cc6342141cdb39f08a229d548d7b29cadd86",
"target": {
"file": "core/java/android/os/BaseBundle.java",
"function": "initializeFromParcelLocked"
}
},
{
"signature_type": "Line",
"digest": {
"line_hashes": [
"205790670589368183264439125641744582550",
"82884370948115524344035054150705602570",
"216041608029756959842858753474917685482",
"15162155614541361053556508522685827566",
"198194646825072841361354763240243703190",
"114445111499470849178140761363641537159",
"285987342404552339375316945596200232299",
"239707072679711863341443365323514481892",
"26662991357027715929291080339741001944",
"38157301873194198109658333375534443531"
],
"threshold": 0.9
},
"id": "ASB-A-240138318-b61c4053",
"signature_version": "v1",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/d2f9cc6342141cdb39f08a229d548d7b29cadd86",
"target": {
"file": "core/java/android/os/BaseBundle.java"
}
}
],
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/d2f9cc6342141cdb39f08a229d548d7b29cadd86"
]
}