In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "133686240502154279773786091537619108093", "127422999342910536179245695135013393407", "67300099388067396301101616012652645851", "163337302695678712309673231316935163919" ] }, "id": "ASB-A-238605611-3c102533", "source": "https://android.googlesource.com/platform/frameworks/base/+/b9a934064598aa655fab4ce75c8eab6165409670", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/wm/ActivityStack.java" }, "signature_type": "Line" }, { "digest": { "length": 2419.0, "function_hash": "141808979057367176623854081047563148082" }, "id": "ASB-A-238605611-9d53ae64", "source": "https://android.googlesource.com/platform/frameworks/base/+/b9a934064598aa655fab4ce75c8eab6165409670", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/wm/ActivityStack.java", "function": "navigateUpToLocked" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/b9a934064598aa655fab4ce75c8eab6165409670" ], "spl": "2022-11-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 2639.0, "function_hash": "163152809231710033579916402524672977404" }, "id": "ASB-A-238605611-91108326", "source": "https://android.googlesource.com/platform/frameworks/base/+/834812c423f10deb95953d41a7007d4cba78f1ec", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/wm/ActivityStack.java", "function": "navigateUpTo" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "296617296869850907267513721048240912212", "263685780514689924530157676118455628991", "184954184224360563554526753095394000592", "274708570523028382735820840000386689045" ] }, "id": "ASB-A-238605611-9b024acd", "source": "https://android.googlesource.com/platform/frameworks/base/+/834812c423f10deb95953d41a7007d4cba78f1ec", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/wm/ActivityStack.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/834812c423f10deb95953d41a7007d4cba78f1ec" ], "spl": "2022-11-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "296617296869850907267513721048240912212", "263685780514689924530157676118455628991", "184954184224360563554526753095394000592", "274708570523028382735820840000386689045" ] }, "id": "ASB-A-238605611-0ce50a76", "source": "https://android.googlesource.com/platform/frameworks/base/+/89ebc8c43f7d2aeaee4fdcf667f07aa98404981d", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/wm/Task.java" }, "signature_type": "Line" }, { "digest": { "length": 2639.0, "function_hash": "163152809231710033579916402524672977404" }, "id": "ASB-A-238605611-f2e80d05", "source": "https://android.googlesource.com/platform/frameworks/base/+/89ebc8c43f7d2aeaee4fdcf667f07aa98404981d", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/wm/Task.java", "function": "navigateUpTo" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/89ebc8c43f7d2aeaee4fdcf667f07aa98404981d" ], "spl": "2022-11-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "296617296869850907267513721048240912212", "263685780514689924530157676118455628991", "184954184224360563554526753095394000592", "274708570523028382735820840000386689045" ] }, "id": "ASB-A-238605611-23f76833", "source": "https://android.googlesource.com/platform/frameworks/base/+/89ebc8c43f7d2aeaee4fdcf667f07aa98404981d", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/wm/Task.java" }, "signature_type": "Line" }, { "digest": { "length": 2639.0, "function_hash": "163152809231710033579916402524672977404" }, "id": "ASB-A-238605611-b8dfb5b3", "source": "https://android.googlesource.com/platform/frameworks/base/+/89ebc8c43f7d2aeaee4fdcf667f07aa98404981d", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/wm/Task.java", "function": "navigateUpTo" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/89ebc8c43f7d2aeaee4fdcf667f07aa98404981d" ], "spl": "2022-11-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "296617296869850907267513721048240912212", "263685780514689924530157676118455628991", "184954184224360563554526753095394000592", "274708570523028382735820840000386689045" ] }, "id": "ASB-A-238605611-4db27a7c", "source": "https://android.googlesource.com/platform/frameworks/base/+/4c355690494f17c8ebdecbc8b1a1eaef21ffc0f3", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/wm/Task.java" }, "signature_type": "Line" }, { "digest": { "length": 2633.0, "function_hash": "253823414916555359442814760992698480359" }, "id": "ASB-A-238605611-70327b87", "source": "https://android.googlesource.com/platform/frameworks/base/+/4c355690494f17c8ebdecbc8b1a1eaef21ffc0f3", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/wm/Task.java", "function": "navigateUpTo" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/4c355690494f17c8ebdecbc8b1a1eaef21ffc0f3" ], "spl": "2022-11-01", "severity": "High", "types": [ "EoP" ] }