In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
{ "vanir_signatures": [ { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/70a5a0fd353cc6203d2926627de93786155ae5bc", "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "id": "ASB-A-327749022-29e01610", "signature_version": "v1", "digest": { "line_hashes": [ "19362163005515750643544123919388329013", "290741224690397986418975891065267248161", "219738665414340179411321010363753811153" ], "threshold": 0.9 }, "deprecated": false }, { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/70a5a0fd353cc6203d2926627de93786155ae5bc", "target": { "function": "onCreate", "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "id": "ASB-A-327749022-eee848c8", "signature_version": "v1", "digest": { "length": 2115.0, "function_hash": "238781758302158020989358110392753045614" }, "deprecated": false } ], "severity": "High", "types": [ "EoP" ], "spl": "2024-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/70a5a0fd353cc6203d2926627de93786155ae5bc" ] }
{ "vanir_signatures": [ { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/7f1c4df02d153cb380a6147e86194bec2a564ab7", "target": { "function": "onCreate", "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "id": "ASB-A-327749022-b88389a4", "signature_version": "v1", "digest": { "length": 1116.0, "function_hash": "176407110612666438888725435408799119230" }, "deprecated": false }, { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/7f1c4df02d153cb380a6147e86194bec2a564ab7", "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "id": "ASB-A-327749022-fa66593f", "signature_version": "v1", "digest": { "line_hashes": [ "286508034715687416815902777443473931615", "107208504080865737088335948576554403261", "298868491214440637583172315063625393345", "276588409617583572845412997902157823092" ], "threshold": 0.9 }, "deprecated": false } ], "severity": "High", "types": [ "EoP" ], "spl": "2024-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/7f1c4df02d153cb380a6147e86194bec2a564ab7" ] }
{ "vanir_signatures": [ { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f0db305a6bb41d04ccab2ecd31a56bbff8e85fe", "target": { "function": "onCreate", "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "id": "ASB-A-327749022-20713dc7", "signature_version": "v1", "digest": { "length": 1317.0, "function_hash": "212141030707619259850086931072691727014" }, "deprecated": false }, { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f0db305a6bb41d04ccab2ecd31a56bbff8e85fe", "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "id": "ASB-A-327749022-ad072e31", "signature_version": "v1", "digest": { "line_hashes": [ "286508034715687416815902777443473931615", "107208504080865737088335948576554403261", "248930167963912118203140179375187790429", "284029657598172104678731367095880218079" ], "threshold": 0.9 }, "deprecated": false } ], "severity": "High", "types": [ "EoP" ], "spl": "2024-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/2f0db305a6bb41d04ccab2ecd31a56bbff8e85fe" ] }
{ "vanir_signatures": [ { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/d83f47397e61d5ec04866af20efcb935a58cbdff", "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "id": "ASB-A-327749022-e43608ee", "signature_version": "v1", "digest": { "line_hashes": [ "19362163005515750643544123919388329013", "290741224690397986418975891065267248161", "219738665414340179411321010363753811153" ], "threshold": 0.9 }, "deprecated": false }, { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/d83f47397e61d5ec04866af20efcb935a58cbdff", "target": { "function": "onCreate", "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "id": "ASB-A-327749022-f3483d58", "signature_version": "v1", "digest": { "length": 1985.0, "function_hash": "285333677698393631617662155273995837399" }, "deprecated": false } ], "severity": "High", "types": [ "EoP" ], "spl": "2024-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/d83f47397e61d5ec04866af20efcb935a58cbdff" ] }
{ "vanir_signatures": [ { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/c02f4ee1936ec5aea5231ebe5afcef27f4bd751c", "target": { "function": "onCreate", "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "id": "ASB-A-327749022-30c1b188", "signature_version": "v1", "digest": { "length": 2115.0, "function_hash": "238781758302158020989358110392753045614" }, "deprecated": false }, { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/c02f4ee1936ec5aea5231ebe5afcef27f4bd751c", "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "id": "ASB-A-327749022-e85c1040", "signature_version": "v1", "digest": { "line_hashes": [ "19362163005515750643544123919388329013", "290741224690397986418975891065267248161", "219738665414340179411321010363753811153" ], "threshold": 0.9 }, "deprecated": false } ], "severity": "High", "types": [ "EoP" ], "spl": "2024-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/c02f4ee1936ec5aea5231ebe5afcef27f4bd751c" ] }