{"id":"ASB-A-242846316","details":"In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.","aliases":["A-242846316","CVE-2022-20493"],"modified":"2026-05-22T15:55:21.353668239Z","published":"2023-01-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2023-01-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/base/+/81352c3775949c622441e10b468766441e35edc7"}],"affected":[{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2023-01-01"}]}],"versions":["10"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/5cb217fff3bc7184bd776a9dc2991e7fce5e25bd"],"severity":"High","vanir_signatures":[{"source":"https://android.googlesource.com/platform/frameworks/base/+/5cb217fff3bc7184bd776a9dc2991e7fce5e25bd","signature_version":"v1","digest":{"length":486,"function_hash":"11074334164627762438878905038171332385"},"target":{"function":"Condition","file":"core/java/android/service/notification/Condition.java"},"id":"ASB-A-242846316-066f1cec","deprecated":false,"signature_type":"Function"},{"source":"https://android.googlesource.com/platform/frameworks/base/+/5cb217fff3bc7184bd776a9dc2991e7fce5e25bd","signature_version":"v1","digest":{"line_hashes":["252915858252393181858950285272959384341","278788551280931953272905500688785716843","258961808285613334958231566506346741020","298032798433109205566535582839433436025","39019814747014903180775230981152272039","213999347382142169190774008544742513719","257292537651431398061326789242835962132","328602949385755024560867337761046241673","280378460480286592607941732109799232646","142497321471513106035507800922636573045","185427983472574071408351209758204325985","69077207884892083112048340671921288585","121387875293937742678138289579632119908","195559258500053957149842765219060401240","172636395093802334379906374061159305157","91590196517595584562729079970903847725","210606271517317925653848038536919990692"],"threshold":0.9},"target":{"file":"core/java/android/service/notification/Condition.java"},"id":"ASB-A-242846316-8c9b0045","signature_type":"Line","deprecated":false}],"spl":"2023-01-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-242846316.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2023-01-01"}]}],"versions":["11"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/80c0fcf06d5a862c4b05be9896a5d320d2f71fb2"],"severity":"High","vanir_signatures":[{"source":"https://android.googlesource.com/platform/frameworks/base/+/80c0fcf06d5a862c4b05be9896a5d320d2f71fb2","signature_version":"v1","digest":{"length":486,"function_hash":"11074334164627762438878905038171332385"},"target":{"function":"Condition","file":"core/java/android/service/notification/Condition.java"},"id":"ASB-A-242846316-0eac9824","signature_type":"Function","deprecated":false},{"source":"https://android.googlesource.com/platform/frameworks/base/+/80c0fcf06d5a862c4b05be9896a5d320d2f71fb2","signature_version":"v1","digest":{"line_hashes":["252915858252393181858950285272959384341","278788551280931953272905500688785716843","258961808285613334958231566506346741020","298032798433109205566535582839433436025","39019814747014903180775230981152272039","213999347382142169190774008544742513719","257292537651431398061326789242835962132","328602949385755024560867337761046241673","280378460480286592607941732109799232646","142497321471513106035507800922636573045","185427983472574071408351209758204325985","69077207884892083112048340671921288585","121387875293937742678138289579632119908","195559258500053957149842765219060401240","172636395093802334379906374061159305157","91590196517595584562729079970903847725","210606271517317925653848038536919990692"],"threshold":0.9},"target":{"file":"core/java/android/service/notification/Condition.java"},"id":"ASB-A-242846316-9296ed14","deprecated":false,"signature_type":"Line"}],"spl":"2023-01-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-242846316.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2023-01-01"}]}],"versions":["12"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/7059638be9271303e22b7b3e8aa6d58677f6143b"],"severity":"High","vanir_signatures":[{"source":"https://android.googlesource.com/platform/frameworks/base/+/7059638be9271303e22b7b3e8aa6d58677f6143b","signature_version":"v1","digest":{"length":486,"function_hash":"11074334164627762438878905038171332385"},"target":{"function":"Condition","file":"core/java/android/service/notification/Condition.java"},"id":"ASB-A-242846316-45d216bd","signature_type":"Function","deprecated":false},{"source":"https://android.googlesource.com/platform/frameworks/base/+/7059638be9271303e22b7b3e8aa6d58677f6143b","signature_version":"v1","target":{"file":"core/java/android/service/notification/Condition.java"},"digest":{"line_hashes":["252915858252393181858950285272959384341","278788551280931953272905500688785716843","258961808285613334958231566506346741020","298032798433109205566535582839433436025","39019814747014903180775230981152272039","213999347382142169190774008544742513719","257292537651431398061326789242835962132","328602949385755024560867337761046241673","280378460480286592607941732109799232646","142497321471513106035507800922636573045","185427983472574071408351209758204325985","69077207884892083112048340671921288585","121387875293937742678138289579632119908","195559258500053957149842765219060401240","172636395093802334379906374061159305157","91590196517595584562729079970903847725","210606271517317925653848038536919990692"],"threshold":0.9},"id":"ASB-A-242846316-ddf43a8c","signature_type":"Line","deprecated":false}],"spl":"2023-01-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-242846316.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12L:0"},{"fixed":"12L:2023-01-01"}]}],"versions":["12L"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/73ad3844ac30ba7ca7c269bf50982427e8703354"],"severity":"High","vanir_signatures":[{"source":"https://android.googlesource.com/platform/frameworks/base/+/73ad3844ac30ba7ca7c269bf50982427e8703354","signature_version":"v1","target":{"file":"core/java/android/service/notification/Condition.java"},"digest":{"line_hashes":["252915858252393181858950285272959384341","278788551280931953272905500688785716843","258961808285613334958231566506346741020","298032798433109205566535582839433436025","39019814747014903180775230981152272039","213999347382142169190774008544742513719","257292537651431398061326789242835962132","328602949385755024560867337761046241673","280378460480286592607941732109799232646","142497321471513106035507800922636573045","185427983472574071408351209758204325985","69077207884892083112048340671921288585","121387875293937742678138289579632119908","195559258500053957149842765219060401240","172636395093802334379906374061159305157","91590196517595584562729079970903847725","210606271517317925653848038536919990692"],"threshold":0.9},"id":"ASB-A-242846316-51987162","signature_type":"Line","deprecated":false},{"source":"https://android.googlesource.com/platform/frameworks/base/+/73ad3844ac30ba7ca7c269bf50982427e8703354","signature_version":"v1","digest":{"function_hash":"11074334164627762438878905038171332385","length":486},"target":{"function":"Condition","file":"core/java/android/service/notification/Condition.java"},"id":"ASB-A-242846316-74754805","deprecated":false,"signature_type":"Function"}],"spl":"2023-01-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-242846316.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2023-01-01"}]}],"versions":["13"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/2a506d89f88c665c3d8252bf3762b5843aff1fdf"],"severity":"High","vanir_signatures":[{"source":"https://android.googlesource.com/platform/frameworks/base/+/2a506d89f88c665c3d8252bf3762b5843aff1fdf","signature_version":"v1","target":{"function":"Condition","file":"core/java/android/service/notification/Condition.java"},"digest":{"length":486,"function_hash":"11074334164627762438878905038171332385"},"id":"ASB-A-242846316-28849c55","deprecated":false,"signature_type":"Function"},{"source":"https://android.googlesource.com/platform/frameworks/base/+/2a506d89f88c665c3d8252bf3762b5843aff1fdf","signature_version":"v1","target":{"file":"core/java/android/service/notification/Condition.java"},"digest":{"line_hashes":["252915858252393181858950285272959384341","278788551280931953272905500688785716843","258961808285613334958231566506346741020","298032798433109205566535582839433436025","39019814747014903180775230981152272039","213999347382142169190774008544742513719","257292537651431398061326789242835962132","328602949385755024560867337761046241673","280378460480286592607941732109799232646","142497321471513106035507800922636573045","185427983472574071408351209758204325985","69077207884892083112048340671921288585","38404803694168051923123762133647414418","189238794017205403025077847082237073120","39236405370346344960500407681558973306","91590196517595584562729079970903847725","210606271517317925653848038536919990692"],"threshold":0.9},"id":"ASB-A-242846316-81ee846a","deprecated":false,"signature_type":"Line"}],"spl":"2023-01-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-242846316.json"}}],"schema_version":"1.7.5"}