In sendIntentSender of ActivityManagerService.java, there is a possible background activity launch due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/3ced332ad690e5b308b02db5c9cdd9ca30368c4a", "https://android.googlesource.com/platform/frameworks/base/+/2938b381ca54cf3a62273f51211c1e03d0f1c30a" ], "severity": "High", "vanir_signatures": [ { "signature_version": "v1", "id": "ASB-A-279428283-3d204aec", "target": { "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "335038255429276524038454323612338138144", "52189908253145933550853530888966949310", "319539161340412931621387084461025149733", "43634580241998039454068752916300960690" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/2938b381ca54cf3a62273f51211c1e03d0f1c30a" }, { "signature_version": "v1", "id": "ASB-A-279428283-43f8de52", "target": { "function": "sendIntentSender", "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Function", "deprecated": false, "digest": { "function_hash": "110490386481867728609206147037514794101", "length": 1436.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/3ced332ad690e5b308b02db5c9cdd9ca30368c4a" }, { "signature_version": "v1", "id": "ASB-A-279428283-c8818fc2", "target": { "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "279306771638369018241720821232848455004", "210358430042206711468216526318392565550", "198461291937773931016095045276966779227", "137577347734009331629484361884904765833" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/3ced332ad690e5b308b02db5c9cdd9ca30368c4a" }, { "signature_version": "v1", "id": "ASB-A-279428283-e1abb82e", "target": { "function": "sendIntentSender", "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Function", "deprecated": false, "digest": { "function_hash": "80770233221535031630358024213665470782", "length": 1813.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/2938b381ca54cf3a62273f51211c1e03d0f1c30a" } ], "spl": "2024-05-01", "types": [ "EoP" ] }
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/7a76717b61d8cb90a4987454f34e88417d68608b" ], "severity": "High", "vanir_signatures": [ { "signature_version": "v1", "id": "ASB-A-279428283-08ac27b0", "target": { "function": "sendIntentSender", "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Function", "deprecated": false, "digest": { "function_hash": "26469817460733435141207315558656520357", "length": 708.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/7a76717b61d8cb90a4987454f34e88417d68608b" }, { "signature_version": "v1", "id": "ASB-A-279428283-a4aad4e7", "target": { "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "210358430042206711468216526318392565550", "198461291937773931016095045276966779227", "137577347734009331629484361884904765833", "43634580241998039454068752916300960690" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/7a76717b61d8cb90a4987454f34e88417d68608b" } ], "spl": "2024-05-01", "types": [ "EoP" ] }
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/792a8bd3f47214b805ce95b2c418bf54675713f7" ], "severity": "High", "vanir_signatures": [ { "signature_version": "v1", "id": "ASB-A-279428283-3ef266d0", "target": { "function": "sendIntentSender", "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Function", "deprecated": false, "digest": { "function_hash": "26469817460733435141207315558656520357", "length": 708.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/792a8bd3f47214b805ce95b2c418bf54675713f7" }, { "signature_version": "v1", "id": "ASB-A-279428283-bbe8140c", "target": { "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "210358430042206711468216526318392565550", "198461291937773931016095045276966779227", "137577347734009331629484361884904765833", "43634580241998039454068752916300960690" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/792a8bd3f47214b805ce95b2c418bf54675713f7" } ], "spl": "2024-05-01", "types": [ "EoP" ] }
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/e5069813ecf230b9fe9a3302a2a59c91d1aa6498" ], "severity": "High", "vanir_signatures": [ { "signature_version": "v1", "id": "ASB-A-279428283-3cf28ebf", "target": { "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "210358430042206711468216526318392565550", "198461291937773931016095045276966779227", "137577347734009331629484361884904765833", "43634580241998039454068752916300960690" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/e5069813ecf230b9fe9a3302a2a59c91d1aa6498" }, { "signature_version": "v1", "id": "ASB-A-279428283-44f300f6", "target": { "function": "sendIntentSender", "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Function", "deprecated": false, "digest": { "function_hash": "26469817460733435141207315558656520357", "length": 708.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/e5069813ecf230b9fe9a3302a2a59c91d1aa6498" } ], "spl": "2024-05-01", "types": [ "EoP" ] }
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/6a58836fbdee74e6ba1192814dde0b4597414aa0" ], "severity": "High", "vanir_signatures": [ { "signature_version": "v1", "id": "ASB-A-279428283-32d4676c", "target": { "function": "sendIntentSender", "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Function", "deprecated": false, "digest": { "function_hash": "110490386481867728609206147037514794101", "length": 1436.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/6a58836fbdee74e6ba1192814dde0b4597414aa0" }, { "signature_version": "v1", "id": "ASB-A-279428283-dca57390", "target": { "file": "services/core/java/com/android/server/am/ActivityManagerService.java" }, "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "210358430042206711468216526318392565550", "198461291937773931016095045276966779227", "137577347734009331629484361884904765833", "43634580241998039454068752916300960690" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/6a58836fbdee74e6ba1192814dde0b4597414aa0" } ], "spl": "2024-05-01", "types": [ "EoP" ] }