In canStartSystemGesture of RecentsAnimationDeviceState.java, there is a possible partial lockscreen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "match_only_versions": [ "13-next" ], "digest": { "length": 570.0, "function_hash": "39520551394268165128259926749305286578" }, "id": "ASB-A-242704576-65f5d79e", "source": "https://android.googlesource.com/platform/packages/apps/Launcher3/+/f6d75c98a94d173ae59afc9bd126d1e72d1b28fa", "deprecated": false, "signature_version": "v1", "target": { "file": "quickstep/src/com/android/quickstep/RecentsAnimationDeviceState.java", "function": "canStartSystemGesture" }, "signature_type": "Function" }, { "match_only_versions": [ "13-next" ], "digest": { "threshold": 0.9, "line_hashes": [ "102719750962839407385791588947222463838", "192398667754083967624319640392489945618", "147869945090265815460147442642954745909", "212469280570156389260060368656048795140", "115690231107413696743416074716134821200", "96408429638492063293826040262651225871", "93611003725843149797632887442677585245", "206369322329740277244311259766126667376" ] }, "id": "ASB-A-242704576-979ac7ba", "source": "https://android.googlesource.com/platform/packages/apps/Launcher3/+/f6d75c98a94d173ae59afc9bd126d1e72d1b28fa", "deprecated": false, "signature_version": "v1", "target": { "file": "quickstep/src/com/android/quickstep/RecentsAnimationDeviceState.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Launcher3/+/f6d75c98a94d173ae59afc9bd126d1e72d1b28fa" ], "spl": "2023-06-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "match_only_versions": [ "12L" ], "digest": { "threshold": 0.9, "line_hashes": [ "102719750962839407385791588947222463838", "192398667754083967624319640392489945618", "147869945090265815460147442642954745909", "212469280570156389260060368656048795140", "115690231107413696743416074716134821200", "96408429638492063293826040262651225871", "93611003725843149797632887442677585245", "206369322329740277244311259766126667376" ] }, "id": "ASB-A-242704576-e24ee0ba", "source": "https://android.googlesource.com/platform/packages/apps/Launcher3/+/f6d75c98a94d173ae59afc9bd126d1e72d1b28fa", "deprecated": false, "signature_version": "v1", "target": { "file": "quickstep/src/com/android/quickstep/RecentsAnimationDeviceState.java" }, "signature_type": "Line" }, { "match_only_versions": [ "12L" ], "digest": { "length": 570.0, "function_hash": "39520551394268165128259926749305286578" }, "id": "ASB-A-242704576-ef6a0f97", "source": "https://android.googlesource.com/platform/packages/apps/Launcher3/+/f6d75c98a94d173ae59afc9bd126d1e72d1b28fa", "deprecated": false, "signature_version": "v1", "target": { "file": "quickstep/src/com/android/quickstep/RecentsAnimationDeviceState.java", "function": "canStartSystemGesture" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Launcher3/+/f6d75c98a94d173ae59afc9bd126d1e72d1b28fa" ], "spl": "2023-06-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "match_only_versions": [ "13" ], "digest": { "threshold": 0.9, "line_hashes": [ "102719750962839407385791588947222463838", "192398667754083967624319640392489945618", "147869945090265815460147442642954745909", "212469280570156389260060368656048795140", "115690231107413696743416074716134821200", "96408429638492063293826040262651225871", "93611003725843149797632887442677585245", "206369322329740277244311259766126667376" ] }, "id": "ASB-A-242704576-2e904b19", "source": "https://android.googlesource.com/platform/packages/apps/Launcher3/+/f6d75c98a94d173ae59afc9bd126d1e72d1b28fa", "deprecated": false, "signature_version": "v1", "target": { "file": "quickstep/src/com/android/quickstep/RecentsAnimationDeviceState.java" }, "signature_type": "Line" }, { "match_only_versions": [ "13" ], "digest": { "length": 570.0, "function_hash": "39520551394268165128259926749305286578" }, "id": "ASB-A-242704576-737f46f6", "source": "https://android.googlesource.com/platform/packages/apps/Launcher3/+/f6d75c98a94d173ae59afc9bd126d1e72d1b28fa", "deprecated": false, "signature_version": "v1", "target": { "file": "quickstep/src/com/android/quickstep/RecentsAnimationDeviceState.java", "function": "canStartSystemGesture" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Launcher3/+/f6d75c98a94d173ae59afc9bd126d1e72d1b28fa" ], "spl": "2023-06-01", "severity": "High", "types": [ "ID" ] }