In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"types": [
"EoP"
],
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/737bc87e74763a073b01253cd3d9a35ccfdc0138",
"https://android.googlesource.com/platform/frameworks/base/+/003800764d6180cddb7202e4e46e7bd48b71d4b9"
],
"spl": "2024-09-01",
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"138002153911268528554143659310083762241",
"297455482597830554531229895867445278578",
"239294018139755612860533715583550949084",
"55165090047528802198270063357550666438"
]
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/003800764d6180cddb7202e4e46e7bd48b71d4b9",
"deprecated": false,
"target": {
"file": "core/java/android/net/Uri.java"
},
"id": "ASB-A-261721900-8429262c",
"signature_version": "v1",
"signature_type": "Line"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"104738803165679544444835421662763770740",
"282854974940796504727249461649251767358",
"193301029035352083894885517289582284355",
"189082287069262779762421083968669274300"
]
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/737bc87e74763a073b01253cd3d9a35ccfdc0138",
"deprecated": false,
"target": {
"file": "core/java/android/net/Uri.java"
},
"id": "ASB-A-261721900-a6e6c930",
"signature_version": "v1",
"signature_type": "Line"
}
]
}{
"types": [
"EoP"
],
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/1fd0421801c391dd619cafeeea8d379a9029074a"
],
"spl": "2024-09-01",
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"104738803165679544444835421662763770740",
"282854974940796504727249461649251767358",
"193301029035352083894885517289582284355",
"189082287069262779762421083968669274300"
]
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/1fd0421801c391dd619cafeeea8d379a9029074a",
"deprecated": false,
"target": {
"file": "core/java/android/net/Uri.java"
},
"id": "ASB-A-261721900-605aab26",
"signature_version": "v1",
"signature_type": "Line"
}
]
}{
"types": [
"EoP"
],
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/191944ece5badb3e85969b3ccb9baebd6abb622b"
],
"spl": "2024-09-01",
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"104738803165679544444835421662763770740",
"282854974940796504727249461649251767358",
"193301029035352083894885517289582284355",
"189082287069262779762421083968669274300"
]
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/191944ece5badb3e85969b3ccb9baebd6abb622b",
"deprecated": false,
"target": {
"file": "core/java/android/net/Uri.java"
},
"id": "ASB-A-261721900-7c973e25",
"signature_version": "v1",
"signature_type": "Line"
}
]
}{
"types": [
"EoP"
],
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/841ce92aa1b350c83148ef6fb57bfff617364e1a"
],
"spl": "2024-09-01",
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"104738803165679544444835421662763770740",
"282854974940796504727249461649251767358",
"193301029035352083894885517289582284355",
"189082287069262779762421083968669274300"
]
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/841ce92aa1b350c83148ef6fb57bfff617364e1a",
"deprecated": false,
"target": {
"file": "core/java/android/net/Uri.java"
},
"id": "ASB-A-261721900-0d604c88",
"signature_version": "v1",
"signature_type": "Line"
}
]
}{
"types": [
"EoP"
],
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/557941ca0cf59da66db4fad12c2139ce80922f4a"
],
"spl": "2024-09-01",
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"104738803165679544444835421662763770740",
"282854974940796504727249461649251767358",
"193301029035352083894885517289582284355",
"189082287069262779762421083968669274300"
]
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/557941ca0cf59da66db4fad12c2139ce80922f4a",
"deprecated": false,
"target": {
"file": "core/java/android/net/Uri.java"
},
"id": "ASB-A-261721900-ca180580",
"signature_version": "v1",
"signature_type": "Line"
}
]
}