In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
{
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/70a5a0fd353cc6203d2926627de93786155ae5bc"
],
"vanir_signatures": [
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/com/android/settings/homepage/SettingsHomepageActivity.java"
},
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/70a5a0fd353cc6203d2926627de93786155ae5bc",
"digest": {
"line_hashes": [
"19362163005515750643544123919388329013",
"290741224690397986418975891065267248161",
"219738665414340179411321010363753811153"
],
"threshold": 0.9
},
"id": "ASB-A-327749022-29e01610"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/com/android/settings/homepage/SettingsHomepageActivity.java",
"function": "onCreate"
},
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/70a5a0fd353cc6203d2926627de93786155ae5bc",
"digest": {
"length": 2115.0,
"function_hash": "238781758302158020989358110392753045614"
},
"id": "ASB-A-327749022-eee848c8"
}
],
"types": [
"EoP"
],
"spl": "2024-09-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/7f1c4df02d153cb380a6147e86194bec2a564ab7"
],
"vanir_signatures": [
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/com/android/settings/homepage/SettingsHomepageActivity.java",
"function": "onCreate"
},
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/7f1c4df02d153cb380a6147e86194bec2a564ab7",
"digest": {
"length": 1116.0,
"function_hash": "176407110612666438888725435408799119230"
},
"id": "ASB-A-327749022-b88389a4"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/com/android/settings/homepage/SettingsHomepageActivity.java"
},
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/7f1c4df02d153cb380a6147e86194bec2a564ab7",
"digest": {
"line_hashes": [
"286508034715687416815902777443473931615",
"107208504080865737088335948576554403261",
"298868491214440637583172315063625393345",
"276588409617583572845412997902157823092"
],
"threshold": 0.9
},
"id": "ASB-A-327749022-fa66593f"
}
],
"types": [
"EoP"
],
"spl": "2024-09-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/2f0db305a6bb41d04ccab2ecd31a56bbff8e85fe"
],
"vanir_signatures": [
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/com/android/settings/homepage/SettingsHomepageActivity.java",
"function": "onCreate"
},
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f0db305a6bb41d04ccab2ecd31a56bbff8e85fe",
"digest": {
"length": 1317.0,
"function_hash": "212141030707619259850086931072691727014"
},
"id": "ASB-A-327749022-20713dc7"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/com/android/settings/homepage/SettingsHomepageActivity.java"
},
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f0db305a6bb41d04ccab2ecd31a56bbff8e85fe",
"digest": {
"line_hashes": [
"286508034715687416815902777443473931615",
"107208504080865737088335948576554403261",
"248930167963912118203140179375187790429",
"284029657598172104678731367095880218079"
],
"threshold": 0.9
},
"id": "ASB-A-327749022-ad072e31"
}
],
"types": [
"EoP"
],
"spl": "2024-09-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/d83f47397e61d5ec04866af20efcb935a58cbdff"
],
"vanir_signatures": [
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/com/android/settings/homepage/SettingsHomepageActivity.java"
},
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/d83f47397e61d5ec04866af20efcb935a58cbdff",
"digest": {
"line_hashes": [
"19362163005515750643544123919388329013",
"290741224690397986418975891065267248161",
"219738665414340179411321010363753811153"
],
"threshold": 0.9
},
"id": "ASB-A-327749022-e43608ee"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/com/android/settings/homepage/SettingsHomepageActivity.java",
"function": "onCreate"
},
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/d83f47397e61d5ec04866af20efcb935a58cbdff",
"digest": {
"length": 1985.0,
"function_hash": "285333677698393631617662155273995837399"
},
"id": "ASB-A-327749022-f3483d58"
}
],
"types": [
"EoP"
],
"spl": "2024-09-01",
"severity": "High"
}{
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/c02f4ee1936ec5aea5231ebe5afcef27f4bd751c"
],
"vanir_signatures": [
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/com/android/settings/homepage/SettingsHomepageActivity.java",
"function": "onCreate"
},
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/c02f4ee1936ec5aea5231ebe5afcef27f4bd751c",
"digest": {
"length": 2115.0,
"function_hash": "238781758302158020989358110392753045614"
},
"id": "ASB-A-327749022-30c1b188"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "src/com/android/settings/homepage/SettingsHomepageActivity.java"
},
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/c02f4ee1936ec5aea5231ebe5afcef27f4bd751c",
"digest": {
"line_hashes": [
"19362163005515750643544123919388329013",
"290741224690397986418975891065267248161",
"219738665414340179411321010363753811153"
],
"threshold": 0.9
},
"id": "ASB-A-327749022-e85c1040"
}
],
"types": [
"EoP"
],
"spl": "2024-09-01",
"severity": "High"
}