In writeToParcel of GateKeeperResponse.java, there is a possible parcel format mismatch. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "36759195758799716500470339593499857914", "43508493706120780682209415994849481627", "42695536845890415653534672504368779046", "239175390438734679826583784887107075704" ] }, "id": "ASB-A-220303465-82379a91", "source": "https://android.googlesource.com/platform/frameworks/base/+/46653a91c30245ca29d41d69174813979a910496", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/service/gatekeeper/GateKeeperResponse.java" }, "signature_type": "Line" }, { "digest": { "length": 387.0, "function_hash": "234721301296286211552937633209153828894" }, "id": "ASB-A-220303465-f0802882", "source": "https://android.googlesource.com/platform/frameworks/base/+/46653a91c30245ca29d41d69174813979a910496", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/service/gatekeeper/GateKeeperResponse.java", "function": "writeToParcel" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/46653a91c30245ca29d41d69174813979a910496" ], "spl": "2022-06-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "36759195758799716500470339593499857914", "43508493706120780682209415994849481627", "42695536845890415653534672504368779046", "239175390438734679826583784887107075704" ] }, "id": "ASB-A-220303465-3d9cefd2", "source": "https://android.googlesource.com/platform/frameworks/base/+/658c53c47c0d1b6a74d3c0a72372aaaba16c2516", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/service/gatekeeper/GateKeeperResponse.java" }, "signature_type": "Line" }, { "digest": { "length": 387.0, "function_hash": "234721301296286211552937633209153828894" }, "id": "ASB-A-220303465-c6226601", "source": "https://android.googlesource.com/platform/frameworks/base/+/658c53c47c0d1b6a74d3c0a72372aaaba16c2516", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/service/gatekeeper/GateKeeperResponse.java", "function": "writeToParcel" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/658c53c47c0d1b6a74d3c0a72372aaaba16c2516" ], "spl": "2022-06-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "36759195758799716500470339593499857914", "43508493706120780682209415994849481627", "42695536845890415653534672504368779046", "239175390438734679826583784887107075704" ] }, "id": "ASB-A-220303465-54075721", "source": "https://android.googlesource.com/platform/frameworks/base/+/658c53c47c0d1b6a74d3c0a72372aaaba16c2516", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/service/gatekeeper/GateKeeperResponse.java" }, "signature_type": "Line" }, { "digest": { "length": 387.0, "function_hash": "234721301296286211552937633209153828894" }, "id": "ASB-A-220303465-b54eaf70", "source": "https://android.googlesource.com/platform/frameworks/base/+/658c53c47c0d1b6a74d3c0a72372aaaba16c2516", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/service/gatekeeper/GateKeeperResponse.java", "function": "writeToParcel" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/658c53c47c0d1b6a74d3c0a72372aaaba16c2516" ], "spl": "2022-06-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "36759195758799716500470339593499857914", "43508493706120780682209415994849481627", "42695536845890415653534672504368779046", "239175390438734679826583784887107075704" ] }, "id": "ASB-A-220303465-3e90c173", "source": "https://android.googlesource.com/platform/frameworks/base/+/5d2176df6923a8984e2b81d8eb4b728f01f1c760", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/service/gatekeeper/GateKeeperResponse.java" }, "signature_type": "Line" }, { "digest": { "length": 387.0, "function_hash": "234721301296286211552937633209153828894" }, "id": "ASB-A-220303465-7ed6e48a", "source": "https://android.googlesource.com/platform/frameworks/base/+/5d2176df6923a8984e2b81d8eb4b728f01f1c760", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/service/gatekeeper/GateKeeperResponse.java", "function": "writeToParcel" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/5d2176df6923a8984e2b81d8eb4b728f01f1c760" ], "spl": "2022-06-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "36759195758799716500470339593499857914", "43508493706120780682209415994849481627", "42695536845890415653534672504368779046", "239175390438734679826583784887107075704" ] }, "id": "ASB-A-220303465-6cefea16", "source": "https://android.googlesource.com/platform/frameworks/base/+/5d2176df6923a8984e2b81d8eb4b728f01f1c760", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/service/gatekeeper/GateKeeperResponse.java" }, "signature_type": "Line" }, { "digest": { "length": 387.0, "function_hash": "234721301296286211552937633209153828894" }, "id": "ASB-A-220303465-81c81dfb", "source": "https://android.googlesource.com/platform/frameworks/base/+/5d2176df6923a8984e2b81d8eb4b728f01f1c760", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/service/gatekeeper/GateKeeperResponse.java", "function": "writeToParcel" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/5d2176df6923a8984e2b81d8eb4b728f01f1c760" ], "spl": "2022-06-01", "severity": "High", "types": [ "EoP" ] }