In onCreate of UninstallerActivity, there is a possible way to uninstall an all without informed user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 3379.0, "function_hash": "40410502518686685314548652191135045008" }, "id": "ASB-A-171221302-6808e78e", "source": "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/PackageInstaller/src/com/android/packageinstaller/UninstallerActivity.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "339452049797380972267273120943251287489", "271094028257776096844352744391651480068", "45929723073850113898938742121001615962", "309644852408225531912342484092467992334", "197654040358525845117565211078035345878", "297569614034252644632300537033970598346" ] }, "id": "ASB-A-171221302-83540243", "source": "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/PackageInstaller/src/com/android/packageinstaller/UninstallerActivity.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08" ], "spl": "2021-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "339452049797380972267273120943251287489", "271094028257776096844352744391651480068", "45929723073850113898938742121001615962", "309644852408225531912342484092467992334", "197654040358525845117565211078035345878", "297569614034252644632300537033970598346" ] }, "id": "ASB-A-171221302-0e130137", "source": "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/PackageInstaller/src/com/android/packageinstaller/UninstallerActivity.java" }, "signature_type": "Line" }, { "digest": { "length": 3379.0, "function_hash": "40410502518686685314548652191135045008" }, "id": "ASB-A-171221302-7335ed3a", "source": "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/PackageInstaller/src/com/android/packageinstaller/UninstallerActivity.java", "function": "onCreate" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08" ], "spl": "2021-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "339452049797380972267273120943251287489", "271094028257776096844352744391651480068", "45929723073850113898938742121001615962", "309644852408225531912342484092467992334", "197654040358525845117565211078035345878", "297569614034252644632300537033970598346" ] }, "id": "ASB-A-171221302-12d047b7", "source": "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/PackageInstaller/src/com/android/packageinstaller/UninstallerActivity.java" }, "signature_type": "Line" }, { "digest": { "length": 3379.0, "function_hash": "40410502518686685314548652191135045008" }, "id": "ASB-A-171221302-fb39e0e0", "source": "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/PackageInstaller/src/com/android/packageinstaller/UninstallerActivity.java", "function": "onCreate" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08" ], "spl": "2021-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "339452049797380972267273120943251287489", "271094028257776096844352744391651480068", "45929723073850113898938742121001615962", "309644852408225531912342484092467992334", "197654040358525845117565211078035345878", "297569614034252644632300537033970598346" ] }, "id": "ASB-A-171221302-0e85d4c6", "source": "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/PackageInstaller/src/com/android/packageinstaller/UninstallerActivity.java" }, "signature_type": "Line" }, { "digest": { "length": 3379.0, "function_hash": "40410502518686685314548652191135045008" }, "id": "ASB-A-171221302-3e6c9cb1", "source": "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/PackageInstaller/src/com/android/packageinstaller/UninstallerActivity.java", "function": "onCreate" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08" ], "spl": "2021-02-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 3379.0, "function_hash": "40410502518686685314548652191135045008" }, "id": "ASB-A-171221302-29801a89", "source": "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/PackageInstaller/src/com/android/packageinstaller/UninstallerActivity.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "339452049797380972267273120943251287489", "271094028257776096844352744391651480068", "45929723073850113898938742121001615962", "309644852408225531912342484092467992334", "197654040358525845117565211078035345878", "297569614034252644632300537033970598346" ] }, "id": "ASB-A-171221302-77008ee8", "source": "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08", "deprecated": false, "signature_version": "v1", "target": { "file": "packages/PackageInstaller/src/com/android/packageinstaller/UninstallerActivity.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/90cfe17643aa4ecbe7cbfb1c787217456f764e08" ], "spl": "2021-02-01", "severity": "High", "types": [ "EoP" ] }