In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"types": [
"EoP"
],
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/packages/services/Car/+/1111e31c89e9ed293f1c6947d29819ec85ab1079"
],
"spl": "2026-06-01",
"vanir_signatures": [
{
"deprecated": false,
"target": {
"file": "service/src/com/android/car/admin/CarDevicePolicyService.java"
},
"source": "https://android.googlesource.com/platform/packages/services/Car/+/1111e31c89e9ed293f1c6947d29819ec85ab1079",
"digest": {
"line_hashes": [
"44767551250258431031953702734849958369",
"34130837925024244807862389383809247798",
"180249908577208746982286680634614732620",
"18667617509951792667757384290115491433",
"159776508980834853746518633739865254468",
"267988298681156892568840090451634773194"
],
"threshold": 0.9
},
"id": "ASB-A-351830787-3d541c4b",
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"target": {
"file": "service/src/com/android/car/admin/CarDevicePolicyService.java",
"function": "setUserDisclaimerAcknowledged"
},
"source": "https://android.googlesource.com/platform/packages/services/Car/+/1111e31c89e9ed293f1c6947d29819ec85ab1079",
"signature_version": "v1",
"digest": {
"function_hash": "308408089892732137531149246928219734430",
"length": 321.0
},
"id": "ASB-A-351830787-4a4aacec",
"signature_type": "Function"
},
{
"deprecated": false,
"target": {
"file": "car-lib/src/android/car/admin/CarDevicePolicyManager.java"
},
"signature_type": "Line",
"digest": {
"line_hashes": [
"215098601854161687189435224539068469883",
"190999509749522505711905941354774094166",
"16176578470122675511107209725921522241"
],
"threshold": 0.9
},
"id": "ASB-A-351830787-f64aa601",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Car/+/1111e31c89e9ed293f1c6947d29819ec85ab1079"
}
]
}
{
"types": [
"EoP"
],
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/packages/services/Car/+/6b03abf9c9dbbc35dfd2e64df31f7d19e77445d8"
],
"spl": "2026-06-01",
"vanir_signatures": [
{
"deprecated": false,
"target": {
"file": "service/src/com/android/car/admin/CarDevicePolicyService.java",
"function": "setUserDisclaimerAcknowledged"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Car/+/6b03abf9c9dbbc35dfd2e64df31f7d19e77445d8",
"digest": {
"function_hash": "308408089892732137531149246928219734430",
"length": 321.0
},
"id": "ASB-A-351830787-597275c2"
},
{
"deprecated": false,
"target": {
"file": "service/src/com/android/car/admin/CarDevicePolicyService.java"
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Car/+/6b03abf9c9dbbc35dfd2e64df31f7d19e77445d8",
"digest": {
"line_hashes": [
"44767551250258431031953702734849958369",
"34130837925024244807862389383809247798",
"180249908577208746982286680634614732620",
"18667617509951792667757384290115491433",
"159776508980834853746518633739865254468",
"267988298681156892568840090451634773194"
],
"threshold": 0.9
},
"id": "ASB-A-351830787-90adb68d"
},
{
"deprecated": false,
"target": {
"file": "car-lib/src/android/car/admin/CarDevicePolicyManager.java"
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Car/+/6b03abf9c9dbbc35dfd2e64df31f7d19e77445d8",
"digest": {
"line_hashes": [
"215098601854161687189435224539068469883",
"190999509749522505711905941354774094166",
"16176578470122675511107209725921522241"
],
"threshold": 0.9
},
"id": "ASB-A-351830787-ca50f5cf"
}
]
}
{
"types": [
"EoP"
],
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/packages/services/Car/+/dd8e3f0ca750fd170e4afce0cbf2a9323c43dfe5"
],
"spl": "2026-06-01",
"vanir_signatures": [
{
"deprecated": false,
"target": {
"file": "service/src/com/android/car/admin/CarDevicePolicyService.java"
},
"signature_type": "Line",
"digest": {
"line_hashes": [
"44767551250258431031953702734849958369",
"34130837925024244807862389383809247798",
"180249908577208746982286680634614732620",
"18667617509951792667757384290115491433",
"159776508980834853746518633739865254468",
"267988298681156892568840090451634773194"
],
"threshold": 0.9
},
"id": "ASB-A-351830787-5aad9a21",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Car/+/dd8e3f0ca750fd170e4afce0cbf2a9323c43dfe5"
},
{
"deprecated": false,
"target": {
"file": "car-lib/src/android/car/admin/CarDevicePolicyManager.java"
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Car/+/dd8e3f0ca750fd170e4afce0cbf2a9323c43dfe5",
"digest": {
"line_hashes": [
"131657575367300493001464047003608493032",
"315708547886175091876824329512086417344",
"172507282698332647779934886591643831999"
],
"threshold": 0.9
},
"id": "ASB-A-351830787-b7230511"
},
{
"deprecated": false,
"target": {
"file": "service/src/com/android/car/admin/CarDevicePolicyService.java",
"function": "setUserDisclaimerAcknowledged"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Car/+/dd8e3f0ca750fd170e4afce0cbf2a9323c43dfe5",
"digest": {
"function_hash": "308408089892732137531149246928219734430",
"length": 321.0
},
"id": "ASB-A-351830787-e6706f83"
}
]
}