In keyguardGoingAway of ActivityTaskManagerService.java, there is a possible lock screen bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"severity": "High",
"spl": "2023-12-01",
"vanir_signatures": [
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/bd2aa5d309c5bf8e73161975bd5aba7945b25e84",
"digest": {
"function_hash": "18450793016039751882161471123903104771",
"length": 618.0
},
"id": "ASB-A-288896339-1c661055",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java",
"function": "keyguardGoingAway"
},
"deprecated": false
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/bd2aa5d309c5bf8e73161975bd5aba7945b25e84",
"digest": {
"line_hashes": [
"130489095145400917776813713537007795442",
"278193841134142408998192934093106006356",
"330932791736218819777175471699729872299",
"56211969826742766420930325550656389895",
"127224605848258698820843035590132556834",
"264741881997647552184624361309976979613",
"101117958547520561979416695057660209376"
],
"threshold": 0.9
},
"id": "ASB-A-288896339-2a158430",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java"
},
"deprecated": false
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/bd2aa5d309c5bf8e73161975bd5aba7945b25e84"
],
"types": [
"EoP"
]
}{
"severity": "High",
"spl": "2023-12-01",
"vanir_signatures": [
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/ad8e7e3b1db22684988a179e23639567a4096ca6",
"digest": {
"line_hashes": [
"130489095145400917776813713537007795442",
"104423481067330968789877443750909090044",
"23336195211901233531059176708158255384",
"56211969826742766420930325550656389895",
"127224605848258698820843035590132556834",
"264741881997647552184624361309976979613",
"101117958547520561979416695057660209376"
],
"threshold": 0.9
},
"id": "ASB-A-288896339-10749946",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java"
},
"deprecated": false
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/ad8e7e3b1db22684988a179e23639567a4096ca6",
"digest": {
"function_hash": "220605962547549702920589314919307302123",
"length": 235.0
},
"id": "ASB-A-288896339-6bf98c35",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java",
"function": "keyguardGoingAway"
},
"deprecated": false
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/ad8e7e3b1db22684988a179e23639567a4096ca6"
],
"types": [
"EoP"
]
}{
"severity": "High",
"spl": "2023-12-01",
"vanir_signatures": [
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f28e3eaaf7c91c6b22ef89a9f18bfe081ba5b1e",
"digest": {
"line_hashes": [
"130489095145400917776813713537007795442",
"104423481067330968789877443750909090044",
"23336195211901233531059176708158255384",
"56211969826742766420930325550656389895",
"127224605848258698820843035590132556834",
"264741881997647552184624361309976979613",
"101117958547520561979416695057660209376"
],
"threshold": 0.9
},
"id": "ASB-A-288896339-2cffc941",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java"
},
"deprecated": false
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/7f28e3eaaf7c91c6b22ef89a9f18bfe081ba5b1e",
"digest": {
"function_hash": "220605962547549702920589314919307302123",
"length": 235.0
},
"id": "ASB-A-288896339-79f795f4",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java",
"function": "keyguardGoingAway"
},
"deprecated": false
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/7f28e3eaaf7c91c6b22ef89a9f18bfe081ba5b1e"
],
"types": [
"EoP"
]
}{
"severity": "High",
"spl": "2023-12-01",
"vanir_signatures": [
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/6568e40be92a15def8e0b6da9c3a18633a71cc3b",
"digest": {
"function_hash": "220605962547549702920589314919307302123",
"length": 235.0
},
"id": "ASB-A-288896339-026a0854",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java",
"function": "keyguardGoingAway"
},
"deprecated": false
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/6568e40be92a15def8e0b6da9c3a18633a71cc3b",
"digest": {
"line_hashes": [
"130489095145400917776813713537007795442",
"104423481067330968789877443750909090044",
"23336195211901233531059176708158255384",
"56211969826742766420930325550656389895",
"127224605848258698820843035590132556834",
"264741881997647552184624361309976979613",
"101117958547520561979416695057660209376"
],
"threshold": 0.9
},
"id": "ASB-A-288896339-38c5aaf8",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java"
},
"deprecated": false
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/6568e40be92a15def8e0b6da9c3a18633a71cc3b"
],
"types": [
"EoP"
]
}{
"severity": "High",
"spl": "2023-12-01",
"vanir_signatures": [
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/41bc7c0042f1dd004179f32376f72a8811d83c6e",
"digest": {
"function_hash": "305551150509788336900740638482705596740",
"length": 463.0
},
"id": "ASB-A-288896339-18d69855",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java",
"function": "keyguardGoingAway"
},
"deprecated": false
},
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/41bc7c0042f1dd004179f32376f72a8811d83c6e",
"digest": {
"line_hashes": [
"130489095145400917776813713537007795442",
"104423481067330968789877443750909090044",
"23336195211901233531059176708158255384",
"56211969826742766420930325550656389895",
"127224605848258698820843035590132556834",
"264741881997647552184624361309976979613",
"101117958547520561979416695057660209376"
],
"threshold": 0.9
},
"id": "ASB-A-288896339-a8923c81",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java"
},
"deprecated": false
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/41bc7c0042f1dd004179f32376f72a8811d83c6e"
],
"types": [
"EoP"
]
}{
"severity": "High",
"spl": "2023-12-01",
"vanir_signatures": [
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/d41eb87422d238a5c854e67ef73d300c9d1caf0c",
"digest": {
"line_hashes": [
"130489095145400917776813713537007795442",
"278193841134142408998192934093106006356",
"330932791736218819777175471699729872299",
"56211969826742766420930325550656389895",
"127224605848258698820843035590132556834",
"264741881997647552184624361309976979613",
"101117958547520561979416695057660209376"
],
"threshold": 0.9
},
"id": "ASB-A-288896339-c635eb41",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java"
},
"deprecated": false
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/base/+/d41eb87422d238a5c854e67ef73d300c9d1caf0c",
"digest": {
"function_hash": "18450793016039751882161471123903104771",
"length": 618.0
},
"id": "ASB-A-288896339-fe32f71d",
"target": {
"file": "services/core/java/com/android/server/wm/ActivityTaskManagerService.java",
"function": "keyguardGoingAway"
},
"deprecated": false
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/d41eb87422d238a5c854e67ef73d300c9d1caf0c"
],
"types": [
"EoP"
]
}