In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin user network settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "types": [ "EoP" ], "spl": "2023-03-01", "severity": "Moderate", "vanir_signatures": [ { "source": "https://android.googlesource.com/platform/packages/modules/Wifi/+/6db4ba73e6a101d02131c5849ece6cf5619e377b", "target": { "function": "isTargetSdkLessThanQOrPrivileged", "file": "service/java/com/android/server/wifi/WifiServiceImpl.java" }, "digest": { "function_hash": "300644194795665403119258562246523309226", "length": 360.0 }, "deprecated": false, "id": "PUB-A-255537598-144c845d", "signature_type": "Function", "signature_version": "v1" }, { "source": "https://android.googlesource.com/platform/packages/modules/Wifi/+/6db4ba73e6a101d02131c5849ece6cf5619e377b", "target": { "file": "service/java/com/android/server/wifi/WifiServiceImpl.java" }, "digest": { "line_hashes": [ "114921050774445932766419954125273037652", "24982070248182902993493787616874260263", "332987931762731709008236448683313426795", "195421297787926007786231591004009845693" ], "threshold": 0.9 }, "deprecated": false, "id": "PUB-A-255537598-dbdc6e09", "signature_type": "Line", "signature_version": "v1" } ], "fixes": [ "https://android.googlesource.com/platform/packages/modules/Wifi/+/6db4ba73e6a101d02131c5849ece6cf5619e377b" ] }