In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "types": [ "EoP" ], "severity": "High", "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "143340558747185809380254933061325026984", "257534514749571527937948510657640349511", "159278642280672671660071288836292656749", "134396200308248142750079451699159448350" ] }, "id": "ASB-A-349780950-25b44307", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/c1e79495a49bd4d3e380136fe4bca7ac1a9ed763", "signature_version": "v1", "signature_type": "Line", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" } }, { "digest": { "function_hash": "309758229606791001181744265417467531376", "length": 1137.0 }, "id": "ASB-A-349780950-b55801e4", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/c1e79495a49bd4d3e380136fe4bca7ac1a9ed763", "signature_version": "v1", "signature_type": "Function", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "checkKeyIntent" } } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/c1e79495a49bd4d3e380136fe4bca7ac1a9ed763" ], "spl": "2024-10-01" }
{ "types": [ "EoP" ], "severity": "High", "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "143340558747185809380254933061325026984", "257534514749571527937948510657640349511", "159278642280672671660071288836292656749", "134396200308248142750079451699159448350" ] }, "id": "ASB-A-349780950-04bcb65c", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b", "signature_version": "v1", "signature_type": "Line", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" } }, { "digest": { "function_hash": "53268511586595012843821258720253640874", "length": 1154.0 }, "id": "ASB-A-349780950-5d0366b3", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b", "signature_version": "v1", "signature_type": "Function", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "checkKeyIntent" } } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b" ], "spl": "2024-10-01" }
{ "types": [ "EoP" ], "severity": "High", "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "143340558747185809380254933061325026984", "257534514749571527937948510657640349511", "159278642280672671660071288836292656749", "134396200308248142750079451699159448350" ] }, "id": "ASB-A-349780950-326ee91d", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b", "signature_version": "v1", "signature_type": "Line", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" } }, { "digest": { "function_hash": "53268511586595012843821258720253640874", "length": 1154.0 }, "id": "ASB-A-349780950-872663cd", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b", "signature_version": "v1", "signature_type": "Function", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "checkKeyIntent" } } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b" ], "spl": "2024-10-01" }
{ "types": [ "EoP" ], "severity": "High", "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "143340558747185809380254933061325026984", "257534514749571527937948510657640349511", "159278642280672671660071288836292656749", "134396200308248142750079451699159448350" ] }, "id": "ASB-A-349780950-514ab252", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b", "signature_version": "v1", "signature_type": "Line", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" } }, { "digest": { "function_hash": "53268511586595012843821258720253640874", "length": 1154.0 }, "id": "ASB-A-349780950-9d5598a7", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b", "signature_version": "v1", "signature_type": "Function", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "checkKeyIntent" } } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b" ], "spl": "2024-10-01" }
{ "types": [ "EoP" ], "severity": "High", "vanir_signatures": [ { "digest": { "function_hash": "53268511586595012843821258720253640874", "length": 1154.0 }, "id": "ASB-A-349780950-2114c1ad", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b", "signature_version": "v1", "signature_type": "Function", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java", "function": "checkKeyIntent" } }, { "digest": { "threshold": 0.9, "line_hashes": [ "143340558747185809380254933061325026984", "257534514749571527937948510657640349511", "159278642280672671660071288836292656749", "134396200308248142750079451699159448350" ] }, "id": "ASB-A-349780950-4aee7538", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b", "signature_version": "v1", "signature_type": "Line", "target": { "file": "services/core/java/com/android/server/accounts/AccountManagerService.java" } } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/f483640dfc954f4c6028f8cb35c1582dd1482c4b" ], "spl": "2024-10-01" }