In onStart of BiometricEnrollIntroduction.java, there is a possible way to determine the device's location due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/4ccdeee849d5fef78498ba33cadc525523efcbd7"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/4ccdeee849d5fef78498ba33cadc525523efcbd7",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388528350-a4424c7d",
"digest": {
"threshold": 0.9,
"line_hashes": [
"321552020423724963430102315176576474173",
"315063177975038202939105563201790514533",
"66359847175346602737210161383359809719",
"248639499660196502193965983358244695219",
"60934286536770553773935080717629505595",
"294044000568240924128836564086809215616",
"136213195857382010431644666774537399576",
"131425012677895900634075701018795598123",
"27765541124398137529764707831781443323",
"17528273657218012563607544064370315864",
"300857873024173526057780740524530921912",
"78175845690829680004694913992119905423",
"80664757291765886186206793194030193454",
"214382559747833153964736340160161217228",
"121177577434766770049090914646148144315",
"194728335853198814081158676298429182953",
"37097152100573281578432124542882193487",
"40540024082895131155180839736311077173"
]
},
"signature_type": "Line",
"target": {
"file": "src/com/android/settings/biometrics/BiometricEnrollIntroduction.java"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/638757a3001417a211ba3b72ffc43b6c751437b1"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/638757a3001417a211ba3b72ffc43b6c751437b1",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388528350-8b0b434a",
"digest": {
"threshold": 0.9,
"line_hashes": [
"321552020423724963430102315176576474173",
"315063177975038202939105563201790514533",
"66359847175346602737210161383359809719",
"248639499660196502193965983358244695219",
"60934286536770553773935080717629505595",
"294044000568240924128836564086809215616",
"136213195857382010431644666774537399576",
"131425012677895900634075701018795598123",
"27765541124398137529764707831781443323",
"17528273657218012563607544064370315864",
"300857873024173526057780740524530921912",
"78175845690829680004694913992119905423",
"80664757291765886186206793194030193454",
"214382559747833153964736340160161217228",
"121177577434766770049090914646148144315",
"194728335853198814081158676298429182953",
"37097152100573281578432124542882193487",
"40540024082895131155180839736311077173"
]
},
"signature_type": "Line",
"target": {
"file": "src/com/android/settings/biometrics/BiometricEnrollIntroduction.java"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/9dd5ed1cea0449812775fb76a46f8be2e6862425"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/9dd5ed1cea0449812775fb76a46f8be2e6862425",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388528350-5793f6bf",
"digest": {
"threshold": 0.9,
"line_hashes": [
"321552020423724963430102315176576474173",
"315063177975038202939105563201790514533",
"66359847175346602737210161383359809719",
"248639499660196502193965983358244695219",
"60934286536770553773935080717629505595",
"294044000568240924128836564086809215616",
"136213195857382010431644666774537399576",
"131425012677895900634075701018795598123",
"27765541124398137529764707831781443323",
"17528273657218012563607544064370315864",
"300857873024173526057780740524530921912",
"78175845690829680004694913992119905423",
"80664757291765886186206793194030193454",
"214382559747833153964736340160161217228",
"121177577434766770049090914646148144315",
"194728335853198814081158676298429182953",
"37097152100573281578432124542882193487",
"40540024082895131155180839736311077173"
]
},
"signature_type": "Line",
"target": {
"file": "src/com/android/settings/biometrics/BiometricEnrollIntroduction.java"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/6da8a2b6b85ca806531f6d20e511e4cd171197c4"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/6da8a2b6b85ca806531f6d20e511e4cd171197c4",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388528350-54ada7c2",
"digest": {
"threshold": 0.9,
"line_hashes": [
"321552020423724963430102315176576474173",
"315063177975038202939105563201790514533",
"66359847175346602737210161383359809719",
"296685852313678411056972883291578897176",
"197806886388363117596950926085129439530",
"294044000568240924128836564086809215616",
"126899702032076627595970058608695870112"
]
},
"signature_type": "Line",
"target": {
"file": "src/com/android/settings/biometrics/BiometricEnrollIntroduction.java"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Settings/+/f6a58a3646598c4ce7f01b9c6c3e828877891e87"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f6a58a3646598c4ce7f01b9c6c3e828877891e87",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388528350-c96924ae",
"digest": {
"threshold": 0.9,
"line_hashes": [
"321552020423724963430102315176576474173",
"315063177975038202939105563201790514533",
"66359847175346602737210161383359809719",
"296685852313678411056972883291578897176",
"197806886388363117596950926085129439530",
"294044000568240924128836564086809215616",
"126899702032076627595970058608695870112",
"131425012677895900634075701018795598123",
"27765541124398137529764707831781443323",
"17528273657218012563607544064370315864",
"300857873024173526057780740524530921912",
"78175845690829680004694913992119905423",
"80664757291765886186206793194030193454",
"214382559747833153964736340160161217228",
"121177577434766770049090914646148144315",
"194728335853198814081158676298429182953",
"37097152100573281578432124542882193487",
"40540024082895131155180839736311077173"
]
},
"signature_type": "Line",
"target": {
"file": "src/com/android/settings/biometrics/BiometricEnrollIntroduction.java"
}
}
],
"severity": "High"
}