In checkKeyIntentParceledCorrectly of AccountManagerService.java, there is a possible way to control other running activities due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "105742063094871766937010577244347100362", "41831547722346298418863001400473844494", "210507454749626293904794193921105781012", "171630030037310044988416393019877335182" ] }, "id": "ASB-A-265798288-41663f73", "source": "https://android.googlesource.com/platform/frameworks/base/+/8476b140eed0235df4e8f07d94420a1471191b55", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" }, "signature_type": "Line" }, { "digest": { "length": 724.0, "function_hash": "5312624277853522920463986731625181836" }, "id": "ASB-A-265798288-7bbfd9e5", "source": "https://android.googlesource.com/platform/frameworks/base/+/8476b140eed0235df4e8f07d94420a1471191b55", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "checkKeyIntentParceledCorrectly" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/8476b140eed0235df4e8f07d94420a1471191b55" ], "spl": "2023-09-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "284645906073750632685697538823996009341", "86394597463221776563906047067977057223", "10888822352540682865424533372652671058", "122492226656786962457012965894461988286" ] }, "id": "ASB-A-265798288-1f2eb017", "source": "https://android.googlesource.com/platform/frameworks/base/+/b117b506ec0504ff9eb2fa523e82f1879ecb8cc1", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" }, "signature_type": "Line" }, { "digest": { "length": 692.0, "function_hash": "65087535959933335363694556889345845267" }, "id": "ASB-A-265798288-71ec04b0", "source": "https://android.googlesource.com/platform/frameworks/base/+/b117b506ec0504ff9eb2fa523e82f1879ecb8cc1", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "checkKeyIntentParceledCorrectly" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/b117b506ec0504ff9eb2fa523e82f1879ecb8cc1" ], "spl": "2023-09-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "284645906073750632685697538823996009341", "86394597463221776563906047067977057223", "10888822352540682865424533372652671058", "122492226656786962457012965894461988286" ] }, "id": "ASB-A-265798288-48b8361a", "source": "https://android.googlesource.com/platform/frameworks/base/+/b117b506ec0504ff9eb2fa523e82f1879ecb8cc1", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" }, "signature_type": "Line" }, { "digest": { "length": 692.0, "function_hash": "65087535959933335363694556889345845267" }, "id": "ASB-A-265798288-f868995f", "source": "https://android.googlesource.com/platform/frameworks/base/+/b117b506ec0504ff9eb2fa523e82f1879ecb8cc1", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "checkKeyIntentParceledCorrectly" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/b117b506ec0504ff9eb2fa523e82f1879ecb8cc1" ], "spl": "2023-09-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 692.0, "function_hash": "65087535959933335363694556889345845267" }, "id": "ASB-A-265798288-05d24594", "source": "https://android.googlesource.com/platform/frameworks/base/+/b117b506ec0504ff9eb2fa523e82f1879ecb8cc1", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "checkKeyIntentParceledCorrectly" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "284645906073750632685697538823996009341", "86394597463221776563906047067977057223", "10888822352540682865424533372652671058", "122492226656786962457012965894461988286" ] }, "id": "ASB-A-265798288-115acde3", "source": "https://android.googlesource.com/platform/frameworks/base/+/b117b506ec0504ff9eb2fa523e82f1879ecb8cc1", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/b117b506ec0504ff9eb2fa523e82f1879ecb8cc1" ], "spl": "2023-09-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "105742063094871766937010577244347100362", "41831547722346298418863001400473844494", "210507454749626293904794193921105781012", "171630030037310044988416393019877335182" ] }, "id": "ASB-A-265798288-79cbb13c", "source": "https://android.googlesource.com/platform/frameworks/base/+/8476b140eed0235df4e8f07d94420a1471191b55", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" }, "signature_type": "Line" }, { "digest": { "length": 724.0, "function_hash": "5312624277853522920463986731625181836" }, "id": "ASB-A-265798288-ea7ab32b", "source": "https://android.googlesource.com/platform/frameworks/base/+/8476b140eed0235df4e8f07d94420a1471191b55", "deprecated": true, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "checkKeyIntentParceledCorrectly" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/8476b140eed0235df4e8f07d94420a1471191b55" ], "spl": "2023-09-01", "severity": "High", "types": [ "EoP" ] }