In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "match_only_versions": [ "12" ], "digest": { "threshold": 0.9, "line_hashes": [ "276225167112100087265125330256831204007", "320163482423534612010675777114789837722", "86102312791780717883442502186039514936", "248811002472384000922184042276885804213" ] }, "id": "ASB-A-304280682-5f1d3499", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/MediaProvider.java" }, "signature_type": "Line" }, { "digest": { "length": 11645.0, "function_hash": "176960762856723078896582130596163932412" }, "id": "ASB-A-304280682-76079d56", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/MediaProvider.java", "function": "updateInternal" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a" ], "spl": "2024-11-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "match_only_versions": [ "12L" ], "digest": { "threshold": 0.9, "line_hashes": [ "276225167112100087265125330256831204007", "320163482423534612010675777114789837722", "86102312791780717883442502186039514936", "248811002472384000922184042276885804213" ] }, "id": "ASB-A-304280682-50dd4b18", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/MediaProvider.java" }, "signature_type": "Line" }, { "digest": { "length": 11645.0, "function_hash": "176960762856723078896582130596163932412" }, "id": "ASB-A-304280682-cd744111", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/MediaProvider.java", "function": "updateInternal" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a" ], "spl": "2024-11-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 11645.0, "function_hash": "176960762856723078896582130596163932412" }, "id": "ASB-A-304280682-27221c21", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/MediaProvider.java", "function": "updateInternal" }, "signature_type": "Function" }, { "match_only_versions": [ "15" ], "digest": { "threshold": 0.9, "line_hashes": [ "276225167112100087265125330256831204007", "320163482423534612010675777114789837722", "86102312791780717883442502186039514936", "248811002472384000922184042276885804213" ] }, "id": "ASB-A-304280682-ae47e9ad", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/MediaProvider.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a" ], "spl": "2024-11-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "match_only_versions": [ "13" ], "digest": { "threshold": 0.9, "line_hashes": [ "276225167112100087265125330256831204007", "320163482423534612010675777114789837722", "86102312791780717883442502186039514936", "248811002472384000922184042276885804213" ] }, "id": "ASB-A-304280682-b6b4046f", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/MediaProvider.java" }, "signature_type": "Line" }, { "digest": { "length": 11645.0, "function_hash": "176960762856723078896582130596163932412" }, "id": "ASB-A-304280682-ede2a3ad", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/MediaProvider.java", "function": "updateInternal" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a" ], "spl": "2024-11-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "match_only_versions": [ "14" ], "digest": { "threshold": 0.9, "line_hashes": [ "276225167112100087265125330256831204007", "320163482423534612010675777114789837722", "86102312791780717883442502186039514936", "248811002472384000922184042276885804213" ] }, "id": "ASB-A-304280682-883470c8", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/MediaProvider.java" }, "signature_type": "Line" }, { "digest": { "length": 11645.0, "function_hash": "176960762856723078896582130596163932412" }, "id": "ASB-A-304280682-a623c848", "source": "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/media/MediaProvider.java", "function": "updateInternal" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/MediaProvider/+/33ff6a663eea1fcdd2b422b98722c1dee48a7f6a" ], "spl": "2024-11-01", "severity": "High", "types": [ "EoP" ] }