ASB-A-224585613
Dashboard / Vulnerabilities / ASB-A-224585613
Summary:
Details: In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
References: https://source.android.com/security/bulletin/2022-07-01, https://android.googlesource.com/platform/frameworks/base/+/2ba316f58e4429033caa495cbc22a0d66dd92d15, https://android.googlesource.com/platform/frameworks/base/+/6ba336c0e280183a04ca45b217a7e89f8419d62b, https://android.googlesource.com/platform/frameworks/base/+/0067ba2426506ec7516dcb18bec5f8a68c116fe9, https://android.googlesource.com/platform/frameworks/base/+/16cf824d3a3dab638698ffaa995621ae18cfcf4e, https://android.googlesource.com/platform/frameworks/base/+/187187a31441e44c29d13c1a04c932abc420b709
Affected packages
Package
Name: platform/frameworks/base
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
