{"id":"ASB-A-155650356", "published":"2020-09-01T00:00:00Z", "modified":"2026-04-30T15:48:46.890647439Z", "aliases":["CVE-2020-0386", "A-155650356"], "details":"In onCreate of RequestPermissionActivity.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege allowing an attacker to set Bluetooth discoverability with User execution privileges needed. User interaction is needed for exploitation.", "affected":[{"package":{"name":"platform/packages/apps/Settings", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"8.0:0"}, {"fixed":"8.0:2020-09-01"}]}], "versions":["8.0"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd"], "severity":"High", "spl":"2020-09-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"76424571978460982127846944569121306573", "length":1437}, "id":"ASB-A-155650356-295bf335", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd", "target":{"file":"src/com/android/settings/bluetooth/RequestPermissionActivity.java", "function":"onCreate"}}, {"deprecated":false, "digest":{"line_hashes":["193334489580700699382546484197967930179", "210568158877036514131610585029805921356", "330560786475052843339255174402822919077", "29849708897609241060053348767078249783", "159098608779391246455711322515613932007", "277746007947450883852795201633121224154"], "threshold":0.9}, "id":"ASB-A-155650356-ff32eb53", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd", "target":{"file":"src/com/android/settings/bluetooth/RequestPermissionActivity.java"}}]}}, {"package":{"name":"platform/packages/apps/Settings", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"8.1:0"}, {"fixed":"8.1:2020-09-01"}]}], "versions":["8.1"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd"], "severity":"High", "spl":"2020-09-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"76424571978460982127846944569121306573", "length":1437}, "id":"ASB-A-155650356-37583fbb", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd", "target":{"file":"src/com/android/settings/bluetooth/RequestPermissionActivity.java", "function":"onCreate"}}, {"deprecated":false, "digest":{"line_hashes":["193334489580700699382546484197967930179", "210568158877036514131610585029805921356", "330560786475052843339255174402822919077", "29849708897609241060053348767078249783", "159098608779391246455711322515613932007", "277746007947450883852795201633121224154"], "threshold":0.9}, "id":"ASB-A-155650356-dd19101a", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd", "target":{"file":"src/com/android/settings/bluetooth/RequestPermissionActivity.java"}}]}}, {"package":{"name":"platform/packages/apps/Settings", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"9:0"}, {"fixed":"9:2020-09-01"}]}], "versions":["9"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd"], "severity":"High", "spl":"2020-09-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["193334489580700699382546484197967930179", "210568158877036514131610585029805921356", "330560786475052843339255174402822919077", "29849708897609241060053348767078249783", "159098608779391246455711322515613932007", "277746007947450883852795201633121224154"], "threshold":0.9}, "id":"ASB-A-155650356-802d6f66", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd", "target":{"file":"src/com/android/settings/bluetooth/RequestPermissionActivity.java"}}, {"deprecated":false, "digest":{"function_hash":"76424571978460982127846944569121306573", "length":1437}, "id":"ASB-A-155650356-ec4dc545", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd", "target":{"file":"src/com/android/settings/bluetooth/RequestPermissionActivity.java", "function":"onCreate"}}]}}, {"package":{"name":"platform/packages/apps/Settings", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"10:0"}, {"fixed":"10:2020-09-01"}]}], "versions":["10"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd"], "severity":"High", "spl":"2020-09-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["193334489580700699382546484197967930179", "210568158877036514131610585029805921356", "330560786475052843339255174402822919077", "29849708897609241060053348767078249783", "159098608779391246455711322515613932007", "277746007947450883852795201633121224154"], "threshold":0.9}, "id":"ASB-A-155650356-01bc3848", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd", "target":{"file":"src/com/android/settings/bluetooth/RequestPermissionActivity.java"}}, {"deprecated":false, "digest":{"function_hash":"76424571978460982127846944569121306573", "length":1437}, "id":"ASB-A-155650356-35f7c4dc", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd", "target":{"file":"src/com/android/settings/bluetooth/RequestPermissionActivity.java", "function":"onCreate"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2020-09-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/packages/apps/Settings/+/ba7f6d7d45776254791dea3b1f5d2acc0dc9b2dd"}]}