In createDontSendToRestrictedAppsBundle of PendingIntentUtils.java, there is a possible background activity launch due to a missing check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"241099825926840930441039057166608676248",
"72315391214666178427269974256863588202",
"229267332971896543381079037628777213401",
"238246418762173638730733100177089798393"
]
},
"id": "ASB-A-273729172-332ca0b2",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/fa0b31821d177fe96e1e03bb6dcb2cda8d5a1c49",
"target": {
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
},
{
"digest": {
"length": 222.0,
"function_hash": "231131053177397398437235385677543959304"
},
"id": "ASB-A-273729172-7abdfd0b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/fa0b31821d177fe96e1e03bb6dcb2cda8d5a1c49",
"target": {
"function": "createDontSendToRestrictedAppsBundle",
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/fa0b31821d177fe96e1e03bb6dcb2cda8d5a1c49"
],
"types": [
"EoP"
],
"spl": "2023-12-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 222.0,
"function_hash": "231131053177397398437235385677543959304"
},
"id": "ASB-A-273729172-54590a89",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9",
"target": {
"function": "createDontSendToRestrictedAppsBundle",
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"241099825926840930441039057166608676248",
"72315391214666178427269974256863588202",
"229267332971896543381079037628777213401",
"238246418762173638730733100177089798393"
]
},
"id": "ASB-A-273729172-a1c5f7fc",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9",
"target": {
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9"
],
"types": [
"EoP"
],
"spl": "2023-12-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 222.0,
"function_hash": "231131053177397398437235385677543959304"
},
"id": "ASB-A-273729172-4f8d060a",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9",
"target": {
"function": "createDontSendToRestrictedAppsBundle",
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"241099825926840930441039057166608676248",
"72315391214666178427269974256863588202",
"229267332971896543381079037628777213401",
"238246418762173638730733100177089798393"
]
},
"id": "ASB-A-273729172-5567a548",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9",
"target": {
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9"
],
"types": [
"EoP"
],
"spl": "2023-12-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"241099825926840930441039057166608676248",
"72315391214666178427269974256863588202",
"229267332971896543381079037628777213401",
"238246418762173638730733100177089798393"
]
},
"id": "ASB-A-273729172-451d35fc",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9",
"target": {
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
},
{
"digest": {
"length": 222.0,
"function_hash": "231131053177397398437235385677543959304"
},
"id": "ASB-A-273729172-5890b31b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9",
"target": {
"function": "createDontSendToRestrictedAppsBundle",
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9"
],
"types": [
"EoP"
],
"spl": "2023-12-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"241099825926840930441039057166608676248",
"72315391214666178427269974256863588202",
"229267332971896543381079037628777213401",
"238246418762173638730733100177089798393"
]
},
"id": "ASB-A-273729172-602703d4",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9",
"target": {
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
},
{
"digest": {
"length": 222.0,
"function_hash": "231131053177397398437235385677543959304"
},
"id": "ASB-A-273729172-c830847d",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9",
"target": {
"function": "createDontSendToRestrictedAppsBundle",
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9"
],
"types": [
"EoP"
],
"spl": "2023-12-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"241099825926840930441039057166608676248",
"72315391214666178427269974256863588202",
"229267332971896543381079037628777213401",
"238246418762173638730733100177089798393"
]
},
"id": "ASB-A-273729172-be91f766",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9",
"target": {
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
},
{
"digest": {
"length": 222.0,
"function_hash": "231131053177397398437235385677543959304"
},
"id": "ASB-A-273729172-ece105d8",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9",
"target": {
"function": "createDontSendToRestrictedAppsBundle",
"file": "services/core/java/com/android/server/PendingIntentUtils.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/7f9be7c3c859dc82d37452570d9878b58f6437a9"
],
"types": [
"EoP"
],
"spl": "2023-12-01",
"severity": "High"
}