{"id":"ASB-A-169763814", "published":"2021-01-01T00:00:00Z", "modified":"2026-06-19T15:21:58.810540849Z", "aliases":["CVE-2021-0315", "A-169763814"], "details":"In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.", "affected":[{"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"8.0:0"}, {"fixed":"8.0:2021-01-01"}]}], "versions":["8.0"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e"], "severity":"High", "spl":"2021-01-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["104208141730917070257649039559371589526", "254138100874364622206040049389530075163", "226644938646319112871550352284193669380", "241473707751469749735754335283226179549"], "threshold":0.9}, "id":"ASB-A-169763814-d67df091", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e", "target":{"file":"core/java/android/accounts/GrantCredentialsPermissionActivity.java"}}, {"deprecated":false, "digest":{"function_hash":"267319344881368748418804224921342043478", "length":2207}, "id":"ASB-A-169763814-dc655b24", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e", "target":{"file":"core/java/android/accounts/GrantCredentialsPermissionActivity.java", "function":"onCreate"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"8.1:0"}, {"fixed":"8.1:2021-01-01"}]}], "versions":["8.1"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e"], "severity":"High", "spl":"2021-01-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["104208141730917070257649039559371589526", "254138100874364622206040049389530075163", "226644938646319112871550352284193669380", "241473707751469749735754335283226179549"], "threshold":0.9}, "id":"ASB-A-169763814-28a9a489", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e", "target":{"file":"core/java/android/accounts/GrantCredentialsPermissionActivity.java"}}, {"deprecated":false, "digest":{"function_hash":"267319344881368748418804224921342043478", "length":2207}, "id":"ASB-A-169763814-8095c3c3", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e", "target":{"file":"core/java/android/accounts/GrantCredentialsPermissionActivity.java", "function":"onCreate"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"9:0"}, {"fixed":"9:2021-01-01"}]}], "versions":["9"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e"], "severity":"High", "spl":"2021-01-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["104208141730917070257649039559371589526", "254138100874364622206040049389530075163", "226644938646319112871550352284193669380", "241473707751469749735754335283226179549"], "threshold":0.9}, "id":"ASB-A-169763814-65b53b27", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e", "target":{"file":"core/java/android/accounts/GrantCredentialsPermissionActivity.java"}}, {"deprecated":false, "digest":{"function_hash":"267319344881368748418804224921342043478", "length":2207}, "id":"ASB-A-169763814-824d5678", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e", "target":{"file":"core/java/android/accounts/GrantCredentialsPermissionActivity.java", "function":"onCreate"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"10:0"}, {"fixed":"10:2021-01-01"}]}], "versions":["10"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e"], "severity":"High", "spl":"2021-01-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"267319344881368748418804224921342043478", "length":2207}, "id":"ASB-A-169763814-50f9df4e", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e", "target":{"file":"core/java/android/accounts/GrantCredentialsPermissionActivity.java", "function":"onCreate"}}, {"deprecated":false, "digest":{"line_hashes":["104208141730917070257649039559371589526", "254138100874364622206040049389530075163", "226644938646319112871550352284193669380", "241473707751469749735754335283226179549"], "threshold":0.9}, "id":"ASB-A-169763814-e02c9498", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e", "target":{"file":"core/java/android/accounts/GrantCredentialsPermissionActivity.java"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"11:0"}, {"fixed":"11:2021-01-01"}]}], "versions":["11"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e"], "severity":"High", "spl":"2021-01-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"267319344881368748418804224921342043478", "length":2207}, "id":"ASB-A-169763814-dece2171", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e", "target":{"file":"core/java/android/accounts/GrantCredentialsPermissionActivity.java", "function":"onCreate"}}, {"deprecated":false, "digest":{"line_hashes":["104208141730917070257649039559371589526", "254138100874364622206040049389530075163", "226644938646319112871550352284193669380", "241473707751469749735754335283226179549"], "threshold":0.9}, "id":"ASB-A-169763814-f8bbdb2c", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e", "target":{"file":"core/java/android/accounts/GrantCredentialsPermissionActivity.java"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2021-01-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/frameworks/base/+/828fe0b915f30e22fec03dc1ed2e66220ceebd3e"}]}