In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "severity": "High", "spl": "2024-09-01", "vanir_signatures": [ { "digest": { "line_hashes": [ "138002153911268528554143659310083762241", "297455482597830554531229895867445278578", "239294018139755612860533715583550949084", "55165090047528802198270063357550666438" ], "threshold": 0.9 }, "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/003800764d6180cddb7202e4e46e7bd48b71d4b9", "id": "ASB-A-261721900-8429262c", "signature_version": "v1", "target": { "file": "core/java/android/net/Uri.java" }, "signature_type": "Line" }, { "digest": { "line_hashes": [ "104738803165679544444835421662763770740", "282854974940796504727249461649251767358", "193301029035352083894885517289582284355", "189082287069262779762421083968669274300" ], "threshold": 0.9 }, "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/737bc87e74763a073b01253cd3d9a35ccfdc0138", "id": "ASB-A-261721900-a6e6c930", "signature_version": "v1", "target": { "file": "core/java/android/net/Uri.java" }, "signature_type": "Line" } ], "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/737bc87e74763a073b01253cd3d9a35ccfdc0138", "https://android.googlesource.com/platform/frameworks/base/+/003800764d6180cddb7202e4e46e7bd48b71d4b9" ] }
{ "severity": "High", "spl": "2024-09-01", "vanir_signatures": [ { "digest": { "line_hashes": [ "104738803165679544444835421662763770740", "282854974940796504727249461649251767358", "193301029035352083894885517289582284355", "189082287069262779762421083968669274300" ], "threshold": 0.9 }, "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/1fd0421801c391dd619cafeeea8d379a9029074a", "id": "ASB-A-261721900-605aab26", "signature_version": "v1", "target": { "file": "core/java/android/net/Uri.java" }, "signature_type": "Line" } ], "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/1fd0421801c391dd619cafeeea8d379a9029074a" ] }
{ "severity": "High", "spl": "2024-09-01", "vanir_signatures": [ { "digest": { "line_hashes": [ "104738803165679544444835421662763770740", "282854974940796504727249461649251767358", "193301029035352083894885517289582284355", "189082287069262779762421083968669274300" ], "threshold": 0.9 }, "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/191944ece5badb3e85969b3ccb9baebd6abb622b", "id": "ASB-A-261721900-7c973e25", "signature_version": "v1", "target": { "file": "core/java/android/net/Uri.java" }, "signature_type": "Line" } ], "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/191944ece5badb3e85969b3ccb9baebd6abb622b" ] }
{ "severity": "High", "spl": "2024-09-01", "vanir_signatures": [ { "digest": { "line_hashes": [ "104738803165679544444835421662763770740", "282854974940796504727249461649251767358", "193301029035352083894885517289582284355", "189082287069262779762421083968669274300" ], "threshold": 0.9 }, "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/841ce92aa1b350c83148ef6fb57bfff617364e1a", "id": "ASB-A-261721900-0d604c88", "signature_version": "v1", "target": { "file": "core/java/android/net/Uri.java" }, "signature_type": "Line" } ], "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/841ce92aa1b350c83148ef6fb57bfff617364e1a" ] }
{ "severity": "High", "spl": "2024-09-01", "vanir_signatures": [ { "digest": { "line_hashes": [ "104738803165679544444835421662763770740", "282854974940796504727249461649251767358", "193301029035352083894885517289582284355", "189082287069262779762421083968669274300" ], "threshold": 0.9 }, "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/557941ca0cf59da66db4fad12c2139ce80922f4a", "id": "ASB-A-261721900-ca180580", "signature_version": "v1", "target": { "file": "core/java/android/net/Uri.java" }, "signature_type": "Line" } ], "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/557941ca0cf59da66db4fad12c2139ce80922f4a" ] }