In onCreate of BluetoothPermissionActivity.java, there is a possible permissions bypass due to a tapjacking overlay that obscures the phonebook permissions dialog when a Bluetooth device is connecting. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 1672.0, "function_hash": "283957372759938639053202084223702147766" }, "id": "ASB-A-168504491-2d773399", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/bluetooth/BluetoothPermissionActivity.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "250944033530905846534454752577485705516", "122937250048511402527095431792931943668", "199530790378335151181444141686459706424", "271895689349493703220227463703747319279", "295722616836742729725697328291482862808", "185750522204165730755895989821683933245" ] }, "id": "ASB-A-168504491-9e527575", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/bluetooth/BluetoothPermissionActivity.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f" ], "spl": "2021-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "250944033530905846534454752577485705516", "122937250048511402527095431792931943668", "199530790378335151181444141686459706424", "271895689349493703220227463703747319279", "295722616836742729725697328291482862808", "185750522204165730755895989821683933245" ] }, "id": "ASB-A-168504491-59e2636e", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/bluetooth/BluetoothPermissionActivity.java" }, "signature_type": "Line" }, { "digest": { "length": 1672.0, "function_hash": "283957372759938639053202084223702147766" }, "id": "ASB-A-168504491-921da95a", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/bluetooth/BluetoothPermissionActivity.java", "function": "onCreate" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f" ], "spl": "2021-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "250944033530905846534454752577485705516", "122937250048511402527095431792931943668", "199530790378335151181444141686459706424", "271895689349493703220227463703747319279", "295722616836742729725697328291482862808", "185750522204165730755895989821683933245" ] }, "id": "ASB-A-168504491-147d3790", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/bluetooth/BluetoothPermissionActivity.java" }, "signature_type": "Line" }, { "digest": { "length": 1672.0, "function_hash": "283957372759938639053202084223702147766" }, "id": "ASB-A-168504491-5325b999", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/bluetooth/BluetoothPermissionActivity.java", "function": "onCreate" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f" ], "spl": "2021-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "250944033530905846534454752577485705516", "122937250048511402527095431792931943668", "199530790378335151181444141686459706424", "271895689349493703220227463703747319279", "295722616836742729725697328291482862808", "185750522204165730755895989821683933245" ] }, "id": "ASB-A-168504491-101a28c0", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/bluetooth/BluetoothPermissionActivity.java" }, "signature_type": "Line" }, { "digest": { "length": 1672.0, "function_hash": "283957372759938639053202084223702147766" }, "id": "ASB-A-168504491-e81bfeaf", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/bluetooth/BluetoothPermissionActivity.java", "function": "onCreate" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f" ], "spl": "2021-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 1672.0, "function_hash": "283957372759938639053202084223702147766" }, "id": "ASB-A-168504491-10119289", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/bluetooth/BluetoothPermissionActivity.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "250944033530905846534454752577485705516", "122937250048511402527095431792931943668", "199530790378335151181444141686459706424", "271895689349493703220227463703747319279", "295722616836742729725697328291482862808", "185750522204165730755895989821683933245" ] }, "id": "ASB-A-168504491-48dd7fee", "source": "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/settings/bluetooth/BluetoothPermissionActivity.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Settings/+/763a4d5967503fc46e0759d5e68cc8fbdc02325f" ], "spl": "2021-02-01", "severity": "High", "types": [ "EoP" ] }