In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
{ "spl": "2024-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/70a5a0fd353cc6203d2926627de93786155ae5bc" ], "vanir_signatures": [ { "id": "ASB-A-327749022-29e01610", "signature_version": "v1", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/70a5a0fd353cc6203d2926627de93786155ae5bc", "digest": { "line_hashes": [ "19362163005515750643544123919388329013", "290741224690397986418975891065267248161", "219738665414340179411321010363753811153" ], "threshold": 0.9 }, "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "deprecated": false, "signature_type": "Line" }, { "id": "ASB-A-327749022-eee848c8", "signature_version": "v1", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/70a5a0fd353cc6203d2926627de93786155ae5bc", "digest": { "function_hash": "238781758302158020989358110392753045614", "length": 2115.0 }, "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java", "function": "onCreate" }, "deprecated": false, "signature_type": "Function" } ], "severity": "High", "types": [ "EoP" ] }
{ "spl": "2024-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/7f1c4df02d153cb380a6147e86194bec2a564ab7" ], "vanir_signatures": [ { "id": "ASB-A-327749022-b88389a4", "signature_version": "v1", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/7f1c4df02d153cb380a6147e86194bec2a564ab7", "digest": { "function_hash": "176407110612666438888725435408799119230", "length": 1116.0 }, "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java", "function": "onCreate" }, "deprecated": false, "signature_type": "Function" }, { "id": "ASB-A-327749022-fa66593f", "signature_version": "v1", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/7f1c4df02d153cb380a6147e86194bec2a564ab7", "digest": { "line_hashes": [ "286508034715687416815902777443473931615", "107208504080865737088335948576554403261", "298868491214440637583172315063625393345", "276588409617583572845412997902157823092" ], "threshold": 0.9 }, "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "deprecated": false, "signature_type": "Line" } ], "severity": "High", "types": [ "EoP" ] }
{ "spl": "2024-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/2f0db305a6bb41d04ccab2ecd31a56bbff8e85fe" ], "vanir_signatures": [ { "id": "ASB-A-327749022-20713dc7", "signature_version": "v1", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f0db305a6bb41d04ccab2ecd31a56bbff8e85fe", "digest": { "function_hash": "212141030707619259850086931072691727014", "length": 1317.0 }, "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java", "function": "onCreate" }, "deprecated": false, "signature_type": "Function" }, { "id": "ASB-A-327749022-ad072e31", "signature_version": "v1", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f0db305a6bb41d04ccab2ecd31a56bbff8e85fe", "digest": { "line_hashes": [ "286508034715687416815902777443473931615", "107208504080865737088335948576554403261", "248930167963912118203140179375187790429", "284029657598172104678731367095880218079" ], "threshold": 0.9 }, "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "deprecated": false, "signature_type": "Line" } ], "severity": "High", "types": [ "EoP" ] }
{ "spl": "2024-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/d83f47397e61d5ec04866af20efcb935a58cbdff" ], "vanir_signatures": [ { "id": "ASB-A-327749022-e43608ee", "signature_version": "v1", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/d83f47397e61d5ec04866af20efcb935a58cbdff", "digest": { "line_hashes": [ "19362163005515750643544123919388329013", "290741224690397986418975891065267248161", "219738665414340179411321010363753811153" ], "threshold": 0.9 }, "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "deprecated": false, "signature_type": "Line" }, { "id": "ASB-A-327749022-f3483d58", "signature_version": "v1", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/d83f47397e61d5ec04866af20efcb935a58cbdff", "digest": { "function_hash": "285333677698393631617662155273995837399", "length": 1985.0 }, "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java", "function": "onCreate" }, "deprecated": false, "signature_type": "Function" } ], "severity": "High", "types": [ "EoP" ] }
{ "spl": "2024-09-01", "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/c02f4ee1936ec5aea5231ebe5afcef27f4bd751c" ], "vanir_signatures": [ { "id": "ASB-A-327749022-30c1b188", "signature_version": "v1", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/c02f4ee1936ec5aea5231ebe5afcef27f4bd751c", "digest": { "function_hash": "238781758302158020989358110392753045614", "length": 2115.0 }, "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java", "function": "onCreate" }, "deprecated": false, "signature_type": "Function" }, { "id": "ASB-A-327749022-e85c1040", "signature_version": "v1", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/c02f4ee1936ec5aea5231ebe5afcef27f4bd751c", "digest": { "line_hashes": [ "19362163005515750643544123919388329013", "290741224690397986418975891065267248161", "219738665414340179411321010363753811153" ], "threshold": 0.9 }, "target": { "file": "src/com/android/settings/homepage/SettingsHomepageActivity.java" }, "deprecated": false, "signature_type": "Line" } ], "severity": "High", "types": [ "EoP" ] }