In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
{ "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/1189e24e47571eae86634aeaa7dc60b8fe7f4820" ], "vanir_signatures": [ { "deprecated": false, "signature_type": "Line", "target": { "file": "src/com/android/settings/users/AppRestrictionsFragment.java" }, "signature_version": "v1", "digest": { "line_hashes": [ "288808278330670729518384155171581405255", "29697836505214348898880984028396549576", "243535703406304265612070206715215416863", "53428261918907701004759118644114222698" ], "threshold": 0.9 }, "id": "ASB-A-330722900-34d7bb6c", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/1189e24e47571eae86634aeaa7dc60b8fe7f4820" }, { "deprecated": false, "signature_type": "Function", "target": { "file": "src/com/android/settings/users/AppRestrictionsFragment.java", "function": "onReceive" }, "signature_version": "v1", "digest": { "length": 909.0, "function_hash": "230717605273109341491163985891656733760" }, "id": "ASB-A-330722900-b369f9c0", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/1189e24e47571eae86634aeaa7dc60b8fe7f4820" } ], "spl": "2024-11-01" }
{ "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" ], "vanir_signatures": [ { "deprecated": false, "signature_type": "Line", "target": { "file": "src/com/android/settings/users/AppRestrictionsFragment.java" }, "signature_version": "v1", "digest": { "line_hashes": [ "288808278330670729518384155171581405255", "29697836505214348898880984028396549576", "243535703406304265612070206715215416863", "53428261918907701004759118644114222698" ], "threshold": 0.9 }, "id": "ASB-A-330722900-cfba6d94", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" }, { "deprecated": false, "signature_type": "Function", "target": { "file": "src/com/android/settings/users/AppRestrictionsFragment.java", "function": "onReceive" }, "signature_version": "v1", "digest": { "length": 909.0, "function_hash": "230717605273109341491163985891656733760" }, "id": "ASB-A-330722900-fb246aa4", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" } ], "spl": "2024-11-01" }
{ "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" ], "vanir_signatures": [ { "deprecated": false, "signature_type": "Line", "target": { "file": "src/com/android/settings/users/AppRestrictionsFragment.java" }, "signature_version": "v1", "digest": { "line_hashes": [ "288808278330670729518384155171581405255", "29697836505214348898880984028396549576", "243535703406304265612070206715215416863", "53428261918907701004759118644114222698" ], "threshold": 0.9 }, "id": "ASB-A-330722900-857935a6", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" }, { "deprecated": false, "signature_type": "Function", "target": { "file": "src/com/android/settings/users/AppRestrictionsFragment.java", "function": "onReceive" }, "signature_version": "v1", "digest": { "length": 909.0, "function_hash": "230717605273109341491163985891656733760" }, "id": "ASB-A-330722900-9e1a3ced", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" } ], "spl": "2024-11-01" }
{ "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" ], "vanir_signatures": [ { "deprecated": false, "signature_type": "Function", "target": { "file": "src/com/android/settings/users/AppRestrictionsFragment.java", "function": "onReceive" }, "signature_version": "v1", "digest": { "length": 909.0, "function_hash": "230717605273109341491163985891656733760" }, "id": "ASB-A-330722900-43f8fc24", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "src/com/android/settings/users/AppRestrictionsFragment.java" }, "signature_version": "v1", "digest": { "line_hashes": [ "288808278330670729518384155171581405255", "29697836505214348898880984028396549576", "243535703406304265612070206715215416863", "53428261918907701004759118644114222698" ], "threshold": 0.9 }, "id": "ASB-A-330722900-a369ff1d", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" } ], "spl": "2024-11-01" }
{ "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" ], "vanir_signatures": [ { "deprecated": false, "signature_type": "Function", "target": { "file": "src/com/android/settings/users/AppRestrictionsFragment.java", "function": "onReceive" }, "signature_version": "v1", "digest": { "length": 909.0, "function_hash": "230717605273109341491163985891656733760" }, "id": "ASB-A-330722900-88b3ce76", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" }, { "deprecated": false, "signature_type": "Line", "target": { "file": "src/com/android/settings/users/AppRestrictionsFragment.java" }, "signature_version": "v1", "digest": { "line_hashes": [ "288808278330670729518384155171581405255", "29697836505214348898880984028396549576", "243535703406304265612070206715215416863", "53428261918907701004759118644114222698" ], "threshold": 0.9 }, "id": "ASB-A-330722900-95f1c641", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/2f53e6ab61873ac6c0a6d600afcf77a287395a3e" } ], "spl": "2024-11-01" }