{"id":"ASB-A-242846316", "published":"2023-01-01T00:00:00Z", "modified":"2026-04-30T15:48:46.890647439Z", "aliases":["CVE-2022-20493", "A-242846316"], "details":"In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "affected":[{"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"10:0"}, {"fixed":"10:2023-01-01"}]}], "versions":["10"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/5cb217fff3bc7184bd776a9dc2991e7fce5e25bd"], "severity":"High", "spl":"2023-01-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"11074334164627762438878905038171332385", "length":486}, "id":"ASB-A-242846316-066f1cec", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/5cb217fff3bc7184bd776a9dc2991e7fce5e25bd", "target":{"file":"core/java/android/service/notification/Condition.java", "function":"Condition"}}, {"deprecated":false, "digest":{"line_hashes":["252915858252393181858950285272959384341", "278788551280931953272905500688785716843", "258961808285613334958231566506346741020", "298032798433109205566535582839433436025", "39019814747014903180775230981152272039", "213999347382142169190774008544742513719", "257292537651431398061326789242835962132", "328602949385755024560867337761046241673", "280378460480286592607941732109799232646", "142497321471513106035507800922636573045", "185427983472574071408351209758204325985", "69077207884892083112048340671921288585", "121387875293937742678138289579632119908", "195559258500053957149842765219060401240", "172636395093802334379906374061159305157", "91590196517595584562729079970903847725", "210606271517317925653848038536919990692"], "threshold":0.9}, "id":"ASB-A-242846316-8c9b0045", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/5cb217fff3bc7184bd776a9dc2991e7fce5e25bd", "target":{"file":"core/java/android/service/notification/Condition.java"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"11:0"}, {"fixed":"11:2023-01-01"}]}], "versions":["11"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/80c0fcf06d5a862c4b05be9896a5d320d2f71fb2"], "severity":"High", "spl":"2023-01-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"11074334164627762438878905038171332385", "length":486}, "id":"ASB-A-242846316-0eac9824", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/80c0fcf06d5a862c4b05be9896a5d320d2f71fb2", "target":{"file":"core/java/android/service/notification/Condition.java", "function":"Condition"}}, {"deprecated":false, "digest":{"line_hashes":["252915858252393181858950285272959384341", "278788551280931953272905500688785716843", "258961808285613334958231566506346741020", "298032798433109205566535582839433436025", "39019814747014903180775230981152272039", "213999347382142169190774008544742513719", "257292537651431398061326789242835962132", "328602949385755024560867337761046241673", "280378460480286592607941732109799232646", "142497321471513106035507800922636573045", "185427983472574071408351209758204325985", "69077207884892083112048340671921288585", "121387875293937742678138289579632119908", "195559258500053957149842765219060401240", "172636395093802334379906374061159305157", "91590196517595584562729079970903847725", "210606271517317925653848038536919990692"], "threshold":0.9}, "id":"ASB-A-242846316-9296ed14", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/80c0fcf06d5a862c4b05be9896a5d320d2f71fb2", "target":{"file":"core/java/android/service/notification/Condition.java"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"12:0"}, {"fixed":"12:2023-01-01"}]}], "versions":["12"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/7059638be9271303e22b7b3e8aa6d58677f6143b"], "severity":"High", "spl":"2023-01-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"11074334164627762438878905038171332385", "length":486}, "id":"ASB-A-242846316-45d216bd", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/7059638be9271303e22b7b3e8aa6d58677f6143b", "target":{"file":"core/java/android/service/notification/Condition.java", "function":"Condition"}}, {"deprecated":false, "digest":{"line_hashes":["252915858252393181858950285272959384341", "278788551280931953272905500688785716843", "258961808285613334958231566506346741020", "298032798433109205566535582839433436025", "39019814747014903180775230981152272039", "213999347382142169190774008544742513719", "257292537651431398061326789242835962132", "328602949385755024560867337761046241673", "280378460480286592607941732109799232646", "142497321471513106035507800922636573045", "185427983472574071408351209758204325985", "69077207884892083112048340671921288585", "121387875293937742678138289579632119908", "195559258500053957149842765219060401240", "172636395093802334379906374061159305157", "91590196517595584562729079970903847725", "210606271517317925653848038536919990692"], "threshold":0.9}, "id":"ASB-A-242846316-ddf43a8c", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/7059638be9271303e22b7b3e8aa6d58677f6143b", "target":{"file":"core/java/android/service/notification/Condition.java"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"12L:0"}, {"fixed":"12L:2023-01-01"}]}], "versions":["12L"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/73ad3844ac30ba7ca7c269bf50982427e8703354"], "severity":"High", "spl":"2023-01-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["252915858252393181858950285272959384341", "278788551280931953272905500688785716843", "258961808285613334958231566506346741020", "298032798433109205566535582839433436025", "39019814747014903180775230981152272039", "213999347382142169190774008544742513719", "257292537651431398061326789242835962132", "328602949385755024560867337761046241673", "280378460480286592607941732109799232646", "142497321471513106035507800922636573045", "185427983472574071408351209758204325985", "69077207884892083112048340671921288585", "121387875293937742678138289579632119908", "195559258500053957149842765219060401240", "172636395093802334379906374061159305157", "91590196517595584562729079970903847725", "210606271517317925653848038536919990692"], "threshold":0.9}, "id":"ASB-A-242846316-51987162", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/73ad3844ac30ba7ca7c269bf50982427e8703354", "target":{"file":"core/java/android/service/notification/Condition.java"}}, {"deprecated":false, "digest":{"function_hash":"11074334164627762438878905038171332385", "length":486}, "id":"ASB-A-242846316-74754805", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/73ad3844ac30ba7ca7c269bf50982427e8703354", "target":{"file":"core/java/android/service/notification/Condition.java", "function":"Condition"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"13:0"}, {"fixed":"13:2023-01-01"}]}], "versions":["13"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/2a506d89f88c665c3d8252bf3762b5843aff1fdf"], "severity":"High", "spl":"2023-01-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"11074334164627762438878905038171332385", "length":486}, "id":"ASB-A-242846316-28849c55", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/2a506d89f88c665c3d8252bf3762b5843aff1fdf", "target":{"file":"core/java/android/service/notification/Condition.java", "function":"Condition"}}, {"deprecated":false, "digest":{"line_hashes":["252915858252393181858950285272959384341", "278788551280931953272905500688785716843", "258961808285613334958231566506346741020", "298032798433109205566535582839433436025", "39019814747014903180775230981152272039", "213999347382142169190774008544742513719", "257292537651431398061326789242835962132", "328602949385755024560867337761046241673", "280378460480286592607941732109799232646", "142497321471513106035507800922636573045", "185427983472574071408351209758204325985", "69077207884892083112048340671921288585", "38404803694168051923123762133647414418", "189238794017205403025077847082237073120", "39236405370346344960500407681558973306", "91590196517595584562729079970903847725", "210606271517317925653848038536919990692"], "threshold":0.9}, "id":"ASB-A-242846316-81ee846a", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/2a506d89f88c665c3d8252bf3762b5843aff1fdf", "target":{"file":"core/java/android/service/notification/Condition.java"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2023-01-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/frameworks/base/+/81352c3775949c622441e10b468766441e35edc7"}]}