In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "16830641431705559210486446086715890742", "143998394650110215676555192591849467967", "325566079398684681412276195277187781401", "270707006471848979591977877664679948966", "157790339265301276034066860128610520493", "219157077729158131834211419022094595646", "89118085545473640529270490193888951563", "130452289594865308465424102610160001137" ] }, "id": "ASB-A-243794108-2827860e", "source": "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/app/ActivityOptions.java" }, "signature_type": "Line" }, { "digest": { "length": 5161.0, "function_hash": "74347317448369607769169886222271088978" }, "id": "ASB-A-243794108-b9b71167", "source": "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/am/PendingIntentRecord.java", "function": "sendInner" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "312639803275511109289718482010218955839", "4012613833445150469580569471489681800", "315751273564067820636973858556062386937", "201229079492434820120352023187159593756", "304922323653536617416328131915865339437", "320670520838781722716483219607694679574", "219150996124357935649781347210418884962", "119496144356418631281332465026025587511" ] }, "id": "ASB-A-243794108-bb7a3e13", "source": "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/am/PendingIntentRecord.java" }, "signature_type": "Line" }, { "digest": { "length": 57.0, "function_hash": "266928651522208641946073042560087418896" }, "id": "ASB-A-243794108-f9cc50c3", "source": "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/app/ActivityOptions.java", "function": "getPendingIntentLaunchFlags" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/c4d3106e347922610f8c554de3ae238175ed393e", "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f" ], "spl": "2023-07-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "16830641431705559210486446086715890742", "143998394650110215676555192591849467967", "325566079398684681412276195277187781401", "270707006471848979591977877664679948966", "157790339265301276034066860128610520493", "219157077729158131834211419022094595646", "89118085545473640529270490193888951563", "130452289594865308465424102610160001137" ] }, "id": "ASB-A-243794108-6baf023e", "source": "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/app/ActivityOptions.java" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "312639803275511109289718482010218955839", "4012613833445150469580569471489681800", "315751273564067820636973858556062386937", "201229079492434820120352023187159593756", "304922323653536617416328131915865339437", "320670520838781722716483219607694679574", "219150996124357935649781347210418884962", "119496144356418631281332465026025587511" ] }, "id": "ASB-A-243794108-95746aec", "source": "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/am/PendingIntentRecord.java" }, "signature_type": "Line" }, { "digest": { "length": 57.0, "function_hash": "266928651522208641946073042560087418896" }, "id": "ASB-A-243794108-dab166bb", "source": "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/app/ActivityOptions.java", "function": "getPendingIntentLaunchFlags" }, "signature_type": "Function" }, { "digest": { "length": 5161.0, "function_hash": "74347317448369607769169886222271088978" }, "id": "ASB-A-243794108-db11e0c3", "source": "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/am/PendingIntentRecord.java", "function": "sendInner" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/c4d3106e347922610f8c554de3ae238175ed393e", "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f" ], "spl": "2023-07-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 57.0, "function_hash": "266928651522208641946073042560087418896" }, "id": "ASB-A-243794108-15e8f5c9", "source": "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/app/ActivityOptions.java", "function": "getPendingIntentLaunchFlags" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "16830641431705559210486446086715890742", "143998394650110215676555192591849467967", "325566079398684681412276195277187781401", "270707006471848979591977877664679948966", "157790339265301276034066860128610520493", "219157077729158131834211419022094595646", "89118085545473640529270490193888951563", "130452289594865308465424102610160001137" ] }, "id": "ASB-A-243794108-3287d704", "source": "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/app/ActivityOptions.java" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "312639803275511109289718482010218955839", "4012613833445150469580569471489681800", "315751273564067820636973858556062386937", "201229079492434820120352023187159593756", "304922323653536617416328131915865339437", "320670520838781722716483219607694679574", "219150996124357935649781347210418884962", "119496144356418631281332465026025587511" ] }, "id": "ASB-A-243794108-3688bb9c", "source": "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/am/PendingIntentRecord.java" }, "signature_type": "Line" }, { "digest": { "length": 5161.0, "function_hash": "74347317448369607769169886222271088978" }, "id": "ASB-A-243794108-a9eb72bf", "source": "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/am/PendingIntentRecord.java", "function": "sendInner" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/c4d3106e347922610f8c554de3ae238175ed393e", "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f" ], "spl": "2023-07-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 57.0, "function_hash": "266928651522208641946073042560087418896" }, "id": "ASB-A-243794108-a8693e1b", "source": "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/app/ActivityOptions.java", "function": "getPendingIntentLaunchFlags" }, "signature_type": "Function" }, { "digest": { "length": 5161.0, "function_hash": "74347317448369607769169886222271088978" }, "id": "ASB-A-243794108-c880d3ea", "source": "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/am/PendingIntentRecord.java", "function": "sendInner" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "312639803275511109289718482010218955839", "4012613833445150469580569471489681800", "315751273564067820636973858556062386937", "201229079492434820120352023187159593756", "304922323653536617416328131915865339437", "320670520838781722716483219607694679574", "219150996124357935649781347210418884962", "119496144356418631281332465026025587511" ] }, "id": "ASB-A-243794108-e04db50a", "source": "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/am/PendingIntentRecord.java" }, "signature_type": "Line" }, { "digest": { "threshold": 0.9, "line_hashes": [ "16830641431705559210486446086715890742", "143998394650110215676555192591849467967", "325566079398684681412276195277187781401", "270707006471848979591977877664679948966", "157790339265301276034066860128610520493", "219157077729158131834211419022094595646", "89118085545473640529270490193888951563", "130452289594865308465424102610160001137" ] }, "id": "ASB-A-243794108-eb418506", "source": "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/app/ActivityOptions.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/c4d3106e347922610f8c554de3ae238175ed393e", "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f" ], "spl": "2023-07-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "16830641431705559210486446086715890742", "143998394650110215676555192591849467967", "325566079398684681412276195277187781401", "270707006471848979591977877664679948966", "157790339265301276034066860128610520493", "219157077729158131834211419022094595646", "89118085545473640529270490193888951563", "130452289594865308465424102610160001137" ] }, "id": "ASB-A-243794108-59c9d537", "source": "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/app/ActivityOptions.java" }, "signature_type": "Line" }, { "digest": { "length": 5161.0, "function_hash": "74347317448369607769169886222271088978" }, "id": "ASB-A-243794108-a0ce7ab6", "source": "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/am/PendingIntentRecord.java", "function": "sendInner" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "312639803275511109289718482010218955839", "4012613833445150469580569471489681800", "315751273564067820636973858556062386937", "201229079492434820120352023187159593756", "304922323653536617416328131915865339437", "320670520838781722716483219607694679574", "219150996124357935649781347210418884962", "119496144356418631281332465026025587511" ] }, "id": "ASB-A-243794108-ab33c3f9", "source": "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "deprecated": false, "signature_version": "v1", "target": { "file": "services/core/java/com/android/server/am/PendingIntentRecord.java" }, "signature_type": "Line" }, { "digest": { "length": 57.0, "function_hash": "266928651522208641946073042560087418896" }, "id": "ASB-A-243794108-f9457d10", "source": "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/app/ActivityOptions.java", "function": "getPendingIntentLaunchFlags" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/c4d3106e347922610f8c554de3ae238175ed393e", "https://android.googlesource.com/platform/frameworks/base/+/48acfb0f1d71912e757cadd505901471c1df4d4c", "https://android.googlesource.com/platform/frameworks/base/+/c62d2e1021a030f4f0ae5fcfc8fe8e0875fa669f" ], "spl": "2023-07-01", "severity": "High", "types": [ "EoP" ] }