In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222166527
{
"binaries": [
{
"binary_version": "8.1.0+r23-3~18.04",
"binary_name": "android-libart"
},
{
"binary_version": "8.1.0+r23-3~18.04",
"binary_name": "dexdump"
},
{
"binary_version": "8.1.0+r23-3~18.04",
"binary_name": "dexlist"
},
{
"binary_version": "8.1.0+r23-3~18.04",
"binary_name": "dmtracedump"
}
]
}{
"binaries": [
{
"binary_version": "8.1.0+r23-3",
"binary_name": "android-libart"
},
{
"binary_version": "8.1.0+r23-3",
"binary_name": "dexdump"
},
{
"binary_version": "8.1.0+r23-3",
"binary_name": "dexlist"
},
{
"binary_version": "8.1.0+r23-3",
"binary_name": "dmtracedump"
}
]
}{
"binaries": [
{
"binary_version": "10.0.0+r36-3",
"binary_name": "android-libart"
},
{
"binary_version": "10.0.0+r36-3",
"binary_name": "dexdump"
},
{
"binary_version": "10.0.0+r36-3",
"binary_name": "dexlist"
},
{
"binary_version": "10.0.0+r36-3",
"binary_name": "dmtracedump"
}
]
}{
"binaries": [
{
"binary_version": "1:29.0.6-4ubuntu1",
"binary_name": "adb"
},
{
"binary_version": "29.0.6-4ubuntu1",
"binary_name": "dmtracedump"
},
{
"binary_version": "29.0.6-4ubuntu1",
"binary_name": "etc1tool"
},
{
"binary_version": "1:29.0.6-4ubuntu1",
"binary_name": "fastboot"
},
{
"binary_version": "29.0.6-4ubuntu1",
"binary_name": "hprof-conv"
}
]
}{
"binaries": [
{
"binary_version": "14.0.0+r15-1ubuntu2",
"binary_name": "android-libart"
},
{
"binary_version": "1:14.0.0+r15-1ubuntu2",
"binary_name": "android-libnativebridge"
},
{
"binary_version": "1:14.0.0+r15-1ubuntu2",
"binary_name": "android-libnativeloader"
},
{
"binary_version": "14.0.0+r15-1ubuntu2",
"binary_name": "dexdump"
},
{
"binary_version": "14.0.0+r15-1ubuntu2",
"binary_name": "dexlist"
},
{
"binary_version": "1:14.0.0+r15-1ubuntu2",
"binary_name": "dmtracedump"
}
]
}{
"binaries": [
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "adb"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libbacktrace"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libbacktrace-dev"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libbase"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libbase-dev"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libcutils"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libcutils-dev"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-liblog"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-liblog-dev"
},
{
"binary_version": "34.0.4-1build3",
"binary_name": "android-libnativehelper"
},
{
"binary_version": "34.0.4-1build3",
"binary_name": "android-libnativehelper-dev"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libsparse"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libsparse-dev"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libutils"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libutils-dev"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libziparchive"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-libziparchive-dev"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-platform-frameworks-native-headers"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-platform-system-core-headers"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "android-sdk-libsparse-utils"
},
{
"binary_version": "34.0.4-1build3",
"binary_name": "etc1tool"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "fastboot"
},
{
"binary_version": "34.0.4-1build3",
"binary_name": "hprof-conv"
},
{
"binary_version": "1:34.0.4-1build3",
"binary_name": "mkbootimg"
}
]
}