In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "267171410303874813593894079500021466037", "1077344172986989022091480265129649824", "284984158789731856620611333402427150396", "163743698811794661076797123244729390081", "49309078779648198447586319556730238094", "175304034582928656411487659945746874956", "323586284942111273280597295068930184713", "189611593811364632483807269674801288677", "269047571403788511934138018445853694945", "149337081138147700610873967459357452909", "340070613973578273727193660536275595076", "235282336187896527707066736756902929197", "163060882746994396021330824611513725512", "19284183937561074316782361006876600473" ] }, "id": "PUB-A-224772678-143251c2", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f53f3e6e41ae1badb43eabc049f1c5b22906ad08", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/wifi/addappnetworks/AddAppNetworksActivity.java" }, "signature_type": "Line" }, { "digest": { "length": 738.0, "function_hash": "210819403355826344848340020988484971332" }, "id": "PUB-A-224772678-79a281a2", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/f53f3e6e41ae1badb43eabc049f1c5b22906ad08", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/wifi/addappnetworks/AddAppNetworksActivity.java", "function": "showAddNetworksFragment" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/f53f3e6e41ae1badb43eabc049f1c5b22906ad08" ], "spl": "2022-12-01", "severity": "Moderate", "types": [ "EoP" ] }