In sendBugreportNotification of BugreportProgressService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
{ "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/a335516ab23c7273f47ae32c7193877cf55939ef" ], "severity": "Moderate", "vanir_signatures": [ { "signature_version": "v1", "id": "PUB-A-178803845-c75d70c1", "target": { "file": "packages/Shell/src/com/android/shell/BugreportProgressService.java" }, "signature_type": "Line", "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "182425166490434187401853962082634870857", "180358564169613106294689196996804806138", "251648940611442324447861438939058327887", "240027564245788170699011703400956372409", "43541929840936321102242559178145437955", "244398771604928538610770729384481943547", "47063428174937537480606106727301330958", "195844079923873832185807390805524702140" ] }, "source": "https://android.googlesource.com/platform/frameworks/base/+/a335516ab23c7273f47ae32c7193877cf55939ef" }, { "signature_version": "v1", "id": "PUB-A-178803845-c827922f", "target": { "function": "sendBugreportNotification", "file": "packages/Shell/src/com/android/shell/BugreportProgressService.java" }, "signature_type": "Function", "deprecated": false, "digest": { "function_hash": "144621175470497648343112472191797387710", "length": 1317.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/a335516ab23c7273f47ae32c7193877cf55939ef" }, { "signature_version": "v1", "id": "PUB-A-178803845-f7aa3c84", "target": { "function": "newCancelIntent", "file": "packages/Shell/src/com/android/shell/BugreportProgressService.java" }, "signature_type": "Function", "deprecated": false, "digest": { "function_hash": "205350091981118751064856942848893731109", "length": 277.0 }, "source": "https://android.googlesource.com/platform/frameworks/base/+/a335516ab23c7273f47ae32c7193877cf55939ef" } ], "spl": "2021-06-01", "types": [ "EoP" ] }