In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
{
"vanir_signatures": [
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"97875093044739988321729097131074856693",
"287133035580790951220081583319943805063",
"227437394994186582862585285252150670956",
"252507859458602345221265720768798435890"
]
},
"id": "PUB-A-178821491-15250e79",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/9bdd5a176d645898484f668b2d969f278af36c64",
"target": {
"file": "src/java/com/android/internal/telephony/Phone.java"
}
}
],
"types": [
"EoP"
],
"severity": "Moderate",
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/9bdd5a176d645898484f668b2d969f278af36c64"
],
"spl": "2021-06-01"
}
{
"vanir_signatures": [
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"function_hash": "191885424736571241062123741644742818904",
"length": 714.0
},
"id": "PUB-A-178821491-24c75c08",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29",
"target": {
"file": "src/com/android/phone/EmergencyCallbackModeExitDialog.java",
"function": "onCreate"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"581241326464807548321198465524489833",
"337309571929948020116541631992926313067",
"130411869554862599324534407931402394784",
"232962272293499536174322120268238608638"
]
},
"id": "PUB-A-178821491-2c5e8399",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29",
"target": {
"file": "src/com/android/phone/EmergencyCallbackModeExitDialog.java"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"function_hash": "303572710079819281089354451874017552225",
"length": 467.0
},
"id": "PUB-A-178821491-a1b82469",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29",
"target": {
"file": "src/com/android/phone/TelephonyShellCommand.java",
"function": "onCommand"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"242536769357434491771664112240486045004",
"259131273019060828105199974790338867272",
"157354404146630464743282028919930120873",
"331851229721322165274794643009480624861",
"212044619527168088405815927135458600052",
"73791009142091792661157833905137520129",
"88241991528623393510090156546042061777",
"220398427435011752809457309792913980802",
"116737567094625170403737053473564651269",
"48997178013455255797895908725834827026",
"28408944132440518107228735906787914263"
]
},
"id": "PUB-A-178821491-ae74758b",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29",
"target": {
"file": "src/com/android/phone/TelephonyShellCommand.java"
}
},
{
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"57347136003091380519346714027142948705",
"82849523835010272212659314052004267301",
"284004370080070990470703405433638750813",
"42424915456844680181980218283527753977",
"146692797791964666847303161980137781588",
"323428823058534547543128631354840325363",
"229640954779443452533459427897680671944",
"269297313775402857032523988072755325019",
"129069491809735648267438589416973391772"
]
},
"id": "PUB-A-178821491-e3a8fa37",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29",
"target": {
"file": "src/com/android/phone/PhoneInterfaceManager.java"
}
}
],
"types": [
"EoP"
],
"severity": "Moderate",
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telephony/+/02dc21559df1d79b5f1aa8b761f2d480c79d3b29"
],
"spl": "2021-06-01"
}