In bind of MediaControlPanel.java, there is a possible way to lock up the system UI using a malicious media file due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 4788.0, "function_hash": "11875377045241804612494561972927168800" }, "id": "PUB-A-180518039-60999e36", "source": "https://android.googlesource.com/platform/frameworks/base/+/95cc34cd98709100eeb7a4ceafdb7c8909f815f9", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/SystemUI/src/com/android/systemui/media/MediaControlPanel.java", "function": "bind" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "269621219306421302996725695851768444324", "107612927170807513447781774362867484314", "146903381778826044182909546161378807500", "280038642060435582262335062436972782086", "33230511008957113053971471463414836006", "316361516433095601078884067218195290494", "278792528406586808387707314654607238079", "96969490361601365046350372389461253407", "61915368849162569221996489561520725636" ] }, "id": "PUB-A-180518039-cca40965", "source": "https://android.googlesource.com/platform/frameworks/base/+/95cc34cd98709100eeb7a4ceafdb7c8909f815f9", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/SystemUI/src/com/android/systemui/media/MediaControlPanel.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/95cc34cd98709100eeb7a4ceafdb7c8909f815f9" ], "spl": "2021-06-01", "severity": "Moderate", "types": [ "DoS" ] }