ASB-A-303835719

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-303835719.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-303835719
Aliases
Published
2023-12-01T00:00:00Z
Modified
2026-04-24T15:37:38.793646Z
Summary
[none]
Details

In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14-next:0
Fixed
14-next:2023-12-01

Affected versions

Other
14-next

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "234226084091455057821822888718178801183",
                    "48161601445990499557773743744981487220",
                    "9581925943886986278467702403361556315",
                    "158744577728783833093806905123284310058",
                    "286497149840698911614324456572265522908",
                    "59805238393357666331782590915338340853",
                    "335502741726855472299662573893601181343",
                    "331794043557624844489300745738168591998"
                ]
            },
            "id": "ASB-A-303835719-7c4531d3",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/a75c8e7b68f9d3ff0eac572190fe2894a768345c",
            "deprecated": false,
            "target": {
                "file": "services/credentials/java/com/android/server/credentials/CredentialManagerUi.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "function_hash": "233515573312489756185313986520921498802",
                "length": 659.0
            },
            "id": "ASB-A-303835719-a03475a6",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/a75c8e7b68f9d3ff0eac572190fe2894a768345c",
            "deprecated": false,
            "target": {
                "function": "createPendingIntent",
                "file": "services/credentials/java/com/android/server/credentials/CredentialManagerUi.java"
            },
            "signature_version": "v1"
        }
    ],
    "types": [
        "ID"
    ],
    "spl": "2023-12-01",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/a75c8e7b68f9d3ff0eac572190fe2894a768345c"
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-303835719.json"

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14:0
Fixed
14:2023-12-01

Affected versions

Other
14

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "function_hash": "233515573312489756185313986520921498802",
                "length": 659.0
            },
            "id": "ASB-A-303835719-5ec58328",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/b9c5b0f408250faa2d8dadd7d2ba8beeb88ea463",
            "deprecated": false,
            "target": {
                "function": "createPendingIntent",
                "file": "services/credentials/java/com/android/server/credentials/CredentialManagerUi.java"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "234226084091455057821822888718178801183",
                    "48161601445990499557773743744981487220",
                    "9581925943886986278467702403361556315",
                    "158744577728783833093806905123284310058",
                    "286497149840698911614324456572265522908",
                    "59805238393357666331782590915338340853",
                    "335502741726855472299662573893601181343",
                    "331794043557624844489300745738168591998"
                ]
            },
            "id": "ASB-A-303835719-d1183d65",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/b9c5b0f408250faa2d8dadd7d2ba8beeb88ea463",
            "deprecated": false,
            "target": {
                "file": "services/credentials/java/com/android/server/credentials/CredentialManagerUi.java"
            },
            "signature_version": "v1"
        }
    ],
    "types": [
        "ID"
    ],
    "spl": "2023-12-01",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/b9c5b0f408250faa2d8dadd7d2ba8beeb88ea463"
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-303835719.json"