ASB-A-331180422

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-331180422.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-331180422
Aliases
  • A-331180422
  • CVE-2024-43090
Published
2024-11-01T00:00:00Z
Modified
2024-11-06T16:12:12.514231Z
Summary
[none]
Details

In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.

References

Affected packages

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15-next:0
Fixed
15-next:2024-11-01

Affected versions

Other

15-next

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "length": 341.0,
                "function_hash": "54232353792406831122485922159119962528"
            },
            "id": "ASB-A-331180422-2834e01d",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/81077e77a1eaf33a5404e0e937ff55e653c2310f",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/statusbar/KeyboardShortcuts.java",
                "function": "showKeyboardShortcuts"
            },
            "signature_type": "Function"
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "79662794345761288633670964133850304054",
                    "267752475476568068293143290709766085662",
                    "108923711353323136876972761715975768327",
                    "237676035118997894609817608285776523298",
                    "316416770399201163962008886285738638469",
                    "229663648195186809592890217714336452057",
                    "31863221223495861764702975528110268691",
                    "78170531166188283539736431015653645959",
                    "185101085428088734066193054446861715345",
                    "56640272557144379983774758783615322358",
                    "244138219046867526925388278881815770060",
                    "158472925963606937155879968582488347473",
                    "44621159645963238539686905178843674202",
                    "299893237819977443792900588820541913036",
                    "19421536555569721606240375099662170290",
                    "239952998978557478720656170484822006187",
                    "265755857815693387043491413353254846891",
                    "85893981219589659662104171184112996272",
                    "219715817232678276017333718146258900296",
                    "208359787522551812512862003336595772190",
                    "64104114683161778879637816510349371064",
                    "112742961271226587000217258312882789077",
                    "224065722189480024582607730702847512740",
                    "175388665894763237357229824311118106016",
                    "242098770994417969077337869609704207034",
                    "77000842006577481222381537519071393423",
                    "288226515297442227675518443597058356719",
                    "88714016036167292730055893350180678889",
                    "99114213992257115560583888034132345431",
                    "153820969308421283079169258464015737746",
                    "157754008045260654863723701290187910549",
                    "140651143403742568184435001470708598746",
                    "258121931572656019073475228651243890462",
                    "23430822753227727446937944712759887137",
                    "174469539869900678912230736737082862443",
                    "142563917058352276748677343362075504247",
                    "201535736067433710330150541574920871556",
                    "48029046808674405942840387122354244086",
                    "91056457920479103625474753947871438932",
                    "293338100379492876604707152843468572731",
                    "88467029880266477051137297341636510686"
                ]
            },
            "id": "ASB-A-331180422-37b9f4fc",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/81077e77a1eaf33a5404e0e937ff55e653c2310f",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/statusbar/KeyboardShortcuts.java"
            },
            "signature_type": "Line"
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "251510458747627072102038153126502039431",
                    "267752475476568068293143290709766085662",
                    "4352831002252024223743999406291225168",
                    "10848701677781521023195575434423677223",
                    "324368060627531187919521534138623687461",
                    "322353686867949188911626149945986147358",
                    "162319429487714975557580418615916830369",
                    "258390822483439492713051771763213202617",
                    "306582760440920185737396692112458178539",
                    "132492600668036463676089312069940063086",
                    "44621159645963238539686905178843674202",
                    "299893237819977443792900588820541913036",
                    "19421536555569721606240375099662170290",
                    "282293828984733645452551191571878659297",
                    "270798074741783214589754904604089214442",
                    "100464154032753156420924656663995215310",
                    "37274810632584452000268501422581290099",
                    "221315897379013072485367143971032475945",
                    "182332769752830845787722265339796099209",
                    "52604886835271388649338880924584286253",
                    "168371443749086070424720635876211818263",
                    "268454076476019019011265770951908440973",
                    "238606799283613637151052253895085086910",
                    "303402091942802102952420643646144412554",
                    "44277018464262944652091173422352067937",
                    "176142224375349354841274445463574783773",
                    "6089382583097789680018940940461889182",
                    "104125399817378292912542634577453909871",
                    "60177601299510323855643891617130912383",
                    "101619280677492538283407676187852407860",
                    "120458130806718076094183958263383503268",
                    "14290941029311219118511359831848816667",
                    "298422700598094422200243569659898753687",
                    "178282516870470891529778160139047743808",
                    "282309509350923935617359022423803623726",
                    "310299380671972283970948176684598153297",
                    "90165110893381291995579768476525660002",
                    "51193125495731809809907160216929261742",
                    "232909560061189942781055841065321332919",
                    "258614017325721270663588198397176057882",
                    "181526793264708243332079886387634886382",
                    "10072484871081055650907708834818909404",
                    "91815599479907456646550431937180945196",
                    "204191377263364916561962202125963993885",
                    "316022300168341702661067429225443458137",
                    "74293198396196528876752704140138229992",
                    "20267624028100076361036287514147533929",
                    "49752213434619799527462900067431389420",
                    "60771081000357533230353724304976842850",
                    "302459403369932028717804777200472682232",
                    "206148093060691258128967879838939791470",
                    "232197418879369548966235340351741159554"
                ]
            },
            "id": "ASB-A-331180422-5aa648ae",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/81077e77a1eaf33a5404e0e937ff55e653c2310f",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/statusbar/KeyboardShortcutListSearch.java"
            },
            "signature_type": "Line"
        },
        {
            "match_only_versions": [
                "15-next"
            ],
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "21562710150279273663297443494454759106",
                    "39776138212295825469958826525124967346",
                    "153626370794078500787699095599010749505",
                    "267451771025146549840246816763090673836",
                    "301585758348631678569076868185810955904",
                    "105410241283867413304423094650987647587",
                    "95215781079759027950825993569339460081",
                    "319667279587503632610717085049774129334",
                    "65895439313164396093401160533900083194"
                ]
            },
            "id": "ASB-A-331180422-95e1dff2",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/81077e77a1eaf33a5404e0e937ff55e653c2310f",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "core/java/android/view/KeyboardShortcutInfo.java"
            },
            "signature_type": "Line"
        },
        {
            "match_only_versions": [
                "15-next"
            ],
            "digest": {
                "length": 175.0,
                "function_hash": "301918192807304444509380514077883882251"
            },
            "id": "ASB-A-331180422-a500af05",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/81077e77a1eaf33a5404e0e937ff55e653c2310f",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/statusbar/KeyboardShortcutListSearch.java",
                "function": "dismissKeyboardShortcuts"
            },
            "signature_type": "Function"
        },
        {
            "digest": {
                "length": 807.0,
                "function_hash": "128632852237960543255231268779165522842"
            },
            "id": "ASB-A-331180422-c36b21fe",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/81077e77a1eaf33a5404e0e937ff55e653c2310f",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/statusbar/KeyboardShortcutListSearch.java",
                "function": "showKeyboardShortcuts"
            },
            "signature_type": "Function"
        },
        {
            "match_only_versions": [
                "15-next"
            ],
            "digest": {
                "length": 142.0,
                "function_hash": "209826785887735042175142190933656405903"
            },
            "id": "ASB-A-331180422-dd54d295",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/81077e77a1eaf33a5404e0e937ff55e653c2310f",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/statusbar/KeyboardShortcuts.java",
                "function": "dismissKeyboardShortcuts"
            },
            "signature_type": "Function"
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/81077e77a1eaf33a5404e0e937ff55e653c2310f"
    ],
    "spl": "2024-11-01",
    "severity": "High",
    "types": [
        "ID"
    ]
}