In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "97875093044739988321729097131074856693", "287133035580790951220081583319943805063", "227437394994186582862585285252150670956", "252507859458602345221265720768798435890" ] }, "id": "PUB-A-178821491-15250e79", "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/9bdd5a176d645898484f668b2d969f278af36c64", "deprecated": false, "signature_version": "v1", "target": { "file": "src/java/com/android/internal/telephony/Phone.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/opt/telephony/+/9bdd5a176d645898484f668b2d969f278af36c64" ], "spl": "2021-06-01", "severity": "Moderate", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 714.0, "function_hash": "191885424736571241062123741644742818904" }, "id": "PUB-A-178821491-24c75c08", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/EmergencyCallbackModeExitDialog.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "581241326464807548321198465524489833", "337309571929948020116541631992926313067", "130411869554862599324534407931402394784", "232962272293499536174322120268238608638" ] }, "id": "PUB-A-178821491-2c5e8399", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/EmergencyCallbackModeExitDialog.java" }, "signature_type": "Line" }, { "digest": { "length": 467.0, "function_hash": "303572710079819281089354451874017552225" }, "id": "PUB-A-178821491-a1b82469", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/TelephonyShellCommand.java", "function": "onCommand" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "242536769357434491771664112240486045004", "259131273019060828105199974790338867272", "157354404146630464743282028919930120873", "331851229721322165274794643009480624861", "212044619527168088405815927135458600052", "73791009142091792661157833905137520129", "88241991528623393510090156546042061777", "220398427435011752809457309792913980802", "116737567094625170403737053473564651269", "48997178013455255797895908725834827026", "28408944132440518107228735906787914263" ] }, "id": "PUB-A-178821491-ae74758b", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/TelephonyShellCommand.java" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "57347136003091380519346714027142948705", "82849523835010272212659314052004267301", "284004370080070990470703405433638750813", "42424915456844680181980218283527753977", "146692797791964666847303161980137781588", "323428823058534547543128631354840325363", "229640954779443452533459427897680671944", "269297313775402857032523988072755325019", "129069491809735648267438589416973391772" ] }, "id": "PUB-A-178821491-e3a8fa37", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/PhoneInterfaceManager.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29" ], "spl": "2021-06-01", "severity": "Moderate", "types": [ "EoP" ] }