In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/3ced332ad690e5b308b02db5c9cdd9ca30368c4a",
"https://android.googlesource.com/platform/frameworks/base/+/2938b381ca54cf3a62273f51211c1e03d0f1c30a"
],
"vanir_signatures": [
{
"digest": {
"line_hashes": [
"335038255429276524038454323612338138144",
"52189908253145933550853530888966949310",
"319539161340412931621387084461025149733",
"43634580241998039454068752916300960690"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-3d204aec",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/2938b381ca54cf3a62273f51211c1e03d0f1c30a"
},
{
"digest": {
"length": 1436.0,
"function_hash": "110490386481867728609206147037514794101"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-43f8de52",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java",
"function": "sendIntentSender"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/3ced332ad690e5b308b02db5c9cdd9ca30368c4a"
},
{
"digest": {
"line_hashes": [
"279306771638369018241720821232848455004",
"210358430042206711468216526318392565550",
"198461291937773931016095045276966779227",
"137577347734009331629484361884904765833"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-c8818fc2",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/3ced332ad690e5b308b02db5c9cdd9ca30368c4a"
},
{
"digest": {
"length": 1813.0,
"function_hash": "80770233221535031630358024213665470782"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-e1abb82e",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java",
"function": "sendIntentSender"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/2938b381ca54cf3a62273f51211c1e03d0f1c30a"
}
],
"severity": "High",
"spl": "2024-05-01",
"types": [
"EoP"
]
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/7a76717b61d8cb90a4987454f34e88417d68608b"
],
"vanir_signatures": [
{
"digest": {
"length": 708.0,
"function_hash": "26469817460733435141207315558656520357"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-08ac27b0",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java",
"function": "sendIntentSender"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/7a76717b61d8cb90a4987454f34e88417d68608b"
},
{
"digest": {
"line_hashes": [
"210358430042206711468216526318392565550",
"198461291937773931016095045276966779227",
"137577347734009331629484361884904765833",
"43634580241998039454068752916300960690"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-a4aad4e7",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/7a76717b61d8cb90a4987454f34e88417d68608b"
}
],
"severity": "High",
"spl": "2024-05-01",
"types": [
"EoP"
]
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/792a8bd3f47214b805ce95b2c418bf54675713f7"
],
"vanir_signatures": [
{
"digest": {
"length": 708.0,
"function_hash": "26469817460733435141207315558656520357"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-3ef266d0",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java",
"function": "sendIntentSender"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/792a8bd3f47214b805ce95b2c418bf54675713f7"
},
{
"digest": {
"line_hashes": [
"210358430042206711468216526318392565550",
"198461291937773931016095045276966779227",
"137577347734009331629484361884904765833",
"43634580241998039454068752916300960690"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-bbe8140c",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/792a8bd3f47214b805ce95b2c418bf54675713f7"
}
],
"severity": "High",
"spl": "2024-05-01",
"types": [
"EoP"
]
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/e5069813ecf230b9fe9a3302a2a59c91d1aa6498"
],
"vanir_signatures": [
{
"digest": {
"line_hashes": [
"210358430042206711468216526318392565550",
"198461291937773931016095045276966779227",
"137577347734009331629484361884904765833",
"43634580241998039454068752916300960690"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-3cf28ebf",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/e5069813ecf230b9fe9a3302a2a59c91d1aa6498"
},
{
"digest": {
"length": 708.0,
"function_hash": "26469817460733435141207315558656520357"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-44f300f6",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java",
"function": "sendIntentSender"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/e5069813ecf230b9fe9a3302a2a59c91d1aa6498"
}
],
"severity": "High",
"spl": "2024-05-01",
"types": [
"EoP"
]
}{
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/6a58836fbdee74e6ba1192814dde0b4597414aa0"
],
"vanir_signatures": [
{
"digest": {
"length": 1436.0,
"function_hash": "110490386481867728609206147037514794101"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-32d4676c",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java",
"function": "sendIntentSender"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6a58836fbdee74e6ba1192814dde0b4597414aa0"
},
{
"digest": {
"line_hashes": [
"210358430042206711468216526318392565550",
"198461291937773931016095045276966779227",
"137577347734009331629484361884904765833",
"43634580241998039454068752916300960690"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-279428283-dca57390",
"target": {
"file": "services/core/java/com/android/server/am/ActivityManagerService.java"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/6a58836fbdee74e6ba1192814dde0b4597414aa0"
}
],
"severity": "High",
"spl": "2024-05-01",
"types": [
"EoP"
]
}