{"id":"ASB-A-270152142","details":"In hasPermissionForActivity of PackageManagerHelper.java, there is a possible way to start arbitrary components due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.","aliases":["A-270152142","CVE-2023-35682"],"modified":"2026-05-22T15:55:21.353668239Z","published":"2023-09-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2023-09-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/apps/Launcher3/+/09f8b0e52e45a0b39bab457534ba2e5ae91ffad0"}],"affected":[{"package":{"name":"platform/packages/apps/Launcher3","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2023-09-01"}]}],"versions":["11"],"ecosystem_specific":{"types":["EoP"],"vanir_signatures":[{"deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442","target":{"file":"src/com/android/launcher3/util/PackageManagerHelper.java"},"id":"ASB-A-270152142-2b13f694","signature_version":"v1","digest":{"line_hashes":["16712015744838485042592019300562064227","31121227761605580680359732024722092718","262702927862700480734688122387108827107","124378739837206776677664547034741575928"],"threshold":0.9},"signature_type":"Line"},{"source":"https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442","digest":{"function_hash":"45317721139558193179461422572059100534","length":650},"target":{"file":"src/com/android/launcher3/util/PackageManagerHelper.java","function":"hasPermissionForActivity"},"deprecated":false,"signature_version":"v1","signature_type":"Function","id":"ASB-A-270152142-ed54c94d"}],"spl":"2023-09-01","severity":"High","fixes":["https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-270152142.json"}},{"package":{"name":"platform/packages/apps/Launcher3","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2023-09-01"}]}],"versions":["12"],"ecosystem_specific":{"types":["EoP"],"vanir_signatures":[{"source":"https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442","digest":{"line_hashes":["16712015744838485042592019300562064227","31121227761605580680359732024722092718","262702927862700480734688122387108827107","124378739837206776677664547034741575928"],"threshold":0.9},"target":{"file":"src/com/android/launcher3/util/PackageManagerHelper.java"},"deprecated":false,"signature_version":"v1","signature_type":"Line","id":"ASB-A-270152142-849c9156"},{"deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442","target":{"file":"src/com/android/launcher3/util/PackageManagerHelper.java","function":"hasPermissionForActivity"},"signature_type":"Function","signature_version":"v1","digest":{"function_hash":"45317721139558193179461422572059100534","length":650},"id":"ASB-A-270152142-912e11fb"}],"spl":"2023-09-01","severity":"High","fixes":["https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-270152142.json"}},{"package":{"name":"platform/packages/apps/Launcher3","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12L:0"},{"fixed":"12L:2023-09-01"}]}],"versions":["12L"],"ecosystem_specific":{"types":["EoP"],"vanir_signatures":[{"deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442","target":{"file":"src/com/android/launcher3/util/PackageManagerHelper.java"},"digest":{"line_hashes":["16712015744838485042592019300562064227","31121227761605580680359732024722092718","262702927862700480734688122387108827107","124378739837206776677664547034741575928"],"threshold":0.9},"signature_version":"v1","signature_type":"Line","id":"ASB-A-270152142-7838c1ba"},{"deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442","target":{"file":"src/com/android/launcher3/util/PackageManagerHelper.java","function":"hasPermissionForActivity"},"signature_type":"Function","signature_version":"v1","digest":{"function_hash":"45317721139558193179461422572059100534","length":650},"id":"ASB-A-270152142-828afd9b"}],"spl":"2023-09-01","severity":"High","fixes":["https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-270152142.json"}},{"package":{"name":"platform/packages/apps/Launcher3","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2023-09-01"}]}],"versions":["13"],"ecosystem_specific":{"types":["EoP"],"vanir_signatures":[{"deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442","target":{"file":"src/com/android/launcher3/util/PackageManagerHelper.java"},"digest":{"threshold":0.9,"line_hashes":["16712015744838485042592019300562064227","31121227761605580680359732024722092718","262702927862700480734688122387108827107","124378739837206776677664547034741575928"]},"signature_version":"v1","signature_type":"Line","id":"ASB-A-270152142-25edf70f"},{"deprecated":false,"source":"https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442","target":{"file":"src/com/android/launcher3/util/PackageManagerHelper.java","function":"hasPermissionForActivity"},"digest":{"function_hash":"45317721139558193179461422572059100534","length":650},"signature_version":"v1","signature_type":"Function","id":"ASB-A-270152142-89afff17"}],"spl":"2023-09-01","fixes":["https://android.googlesource.com/platform/packages/apps/Launcher3/+/c53818a16b4322a823497726ac7e7a44501b4442"],"severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-270152142.json"}}],"schema_version":"1.7.5"}