In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "severity": "High", "types": [ "EoP" ], "spl": "2023-07-01", "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21" ], "vanir_signatures": [ { "deprecated": false, "target": { "function": "updatePictureInPictureMode", "file": "services/core/java/com/android/server/wm/ActivityRecord.java" }, "signature_type": "Function", "digest": { "function_hash": "84463906349357637457593819849224613900", "length": 429.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21", "signature_version": "v1", "id": "ASB-A-265293293-0cfbc7f2" }, { "deprecated": false, "target": { "file": "services/core/java/com/android/server/wm/ActivityRecord.java" }, "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "38811885578589579865256225484930353749", "182937806377545620401941566465606663173", "50687391986007160311991249772947348109", "19085090832050058609389267391752865303" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21", "signature_version": "v1", "id": "ASB-A-265293293-3b846db4" } ] }
{ "severity": "High", "types": [ "EoP" ], "spl": "2023-07-01", "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21" ], "vanir_signatures": [ { "deprecated": false, "target": { "function": "updatePictureInPictureMode", "file": "services/core/java/com/android/server/wm/ActivityRecord.java" }, "signature_type": "Function", "digest": { "function_hash": "84463906349357637457593819849224613900", "length": 429.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21", "signature_version": "v1", "id": "ASB-A-265293293-047a6d7d" }, { "deprecated": false, "target": { "file": "services/core/java/com/android/server/wm/ActivityRecord.java" }, "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "38811885578589579865256225484930353749", "182937806377545620401941566465606663173", "50687391986007160311991249772947348109", "19085090832050058609389267391752865303" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21", "signature_version": "v1", "id": "ASB-A-265293293-3fb8d3fe" } ] }
{ "severity": "High", "types": [ "EoP" ], "spl": "2023-07-01", "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21" ], "vanir_signatures": [ { "deprecated": false, "target": { "file": "services/core/java/com/android/server/wm/ActivityRecord.java" }, "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "38811885578589579865256225484930353749", "182937806377545620401941566465606663173", "50687391986007160311991249772947348109", "19085090832050058609389267391752865303" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21", "signature_version": "v1", "id": "ASB-A-265293293-36bf829f" }, { "deprecated": false, "target": { "function": "updatePictureInPictureMode", "file": "services/core/java/com/android/server/wm/ActivityRecord.java" }, "signature_type": "Function", "digest": { "function_hash": "84463906349357637457593819849224613900", "length": 429.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21", "signature_version": "v1", "id": "ASB-A-265293293-d6c25797" } ] }
{ "severity": "High", "types": [ "EoP" ], "spl": "2023-07-01", "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21" ], "vanir_signatures": [ { "deprecated": false, "target": { "file": "services/core/java/com/android/server/wm/ActivityRecord.java" }, "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "38811885578589579865256225484930353749", "182937806377545620401941566465606663173", "50687391986007160311991249772947348109", "19085090832050058609389267391752865303" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21", "signature_version": "v1", "id": "ASB-A-265293293-4318acab" }, { "deprecated": false, "target": { "function": "updatePictureInPictureMode", "file": "services/core/java/com/android/server/wm/ActivityRecord.java" }, "signature_type": "Function", "digest": { "function_hash": "84463906349357637457593819849224613900", "length": 429.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21", "signature_version": "v1", "id": "ASB-A-265293293-5ab22b4c" } ] }
{ "severity": "High", "types": [ "EoP" ], "spl": "2023-07-01", "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21" ], "vanir_signatures": [ { "deprecated": false, "target": { "file": "services/core/java/com/android/server/wm/ActivityRecord.java" }, "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "38811885578589579865256225484930353749", "182937806377545620401941566465606663173", "50687391986007160311991249772947348109", "19085090832050058609389267391752865303" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21", "signature_version": "v1", "id": "ASB-A-265293293-2ee0aa9f" }, { "deprecated": false, "target": { "function": "updatePictureInPictureMode", "file": "services/core/java/com/android/server/wm/ActivityRecord.java" }, "signature_type": "Function", "digest": { "function_hash": "84463906349357637457593819849224613900", "length": 429.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/4fad1456409b79d6e649a29d5116a4fe3160bd21", "signature_version": "v1", "id": "ASB-A-265293293-b815f286" } ] }