In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7"
],
"spl": "2020-09-01",
"vanir_signatures": [
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7",
"target": {
"function": "addResolutionIntent",
"file": "src/java/com/android/internal/telephony/euicc/EuiccController.java"
},
"deprecated": false,
"digest": {
"function_hash": "124347352249865646556944936559596462054",
"length": 520.0
},
"signature_type": "Function",
"id": "ASB-A-154124307-5f46d6a7"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7",
"target": {
"file": "src/java/com/android/internal/telephony/euicc/EuiccController.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"117644871708654916346245945015463275626",
"223665824716409487639496807541848082315",
"153896511408108601377244622035927833590",
"214338118115568385601977212861965221200",
"252555523724162323221182265734240667994",
"262626998732534039738096859923668305917",
"284733846293931103168905718368524179728",
"295496958192235468506319800338169638268",
"73099640744412732828548186330436131037",
"145124376558202810450310734881358587716",
"227614234266439378251246365778538648135"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "ASB-A-154124307-b1a247c1"
}
],
"types": [
"ID"
]
}{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2"
],
"spl": "2020-09-01",
"vanir_signatures": [
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2",
"target": {
"file": "src/com/android/phone/EmergencyCallbackModeService.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"41947819677962889077519451532663704680",
"102135948322594920735190946348112074288",
"220160467030282996760638356047881540303",
"253889126629877657108515330408653953158",
"276112923747055330083233450457693907914"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "ASB-A-154124307-77c0601b"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2",
"target": {
"function": "showNotification",
"file": "src/com/android/phone/EmergencyCallbackModeService.java"
},
"deprecated": false,
"digest": {
"function_hash": "239929725198670433305970540035158012328",
"length": 1554.0
},
"signature_type": "Function",
"id": "ASB-A-154124307-910531fc"
}
],
"types": [
"ID"
]
}{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7"
],
"spl": "2020-09-01",
"vanir_signatures": [
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7",
"target": {
"file": "src/java/com/android/internal/telephony/euicc/EuiccController.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"117644871708654916346245945015463275626",
"223665824716409487639496807541848082315",
"153896511408108601377244622035927833590",
"214338118115568385601977212861965221200",
"252555523724162323221182265734240667994",
"262626998732534039738096859923668305917",
"284733846293931103168905718368524179728",
"295496958192235468506319800338169638268",
"73099640744412732828548186330436131037",
"145124376558202810450310734881358587716",
"227614234266439378251246365778538648135"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "ASB-A-154124307-319978f2"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7",
"target": {
"function": "addResolutionIntent",
"file": "src/java/com/android/internal/telephony/euicc/EuiccController.java"
},
"deprecated": false,
"digest": {
"function_hash": "124347352249865646556944936559596462054",
"length": 520.0
},
"signature_type": "Function",
"id": "ASB-A-154124307-f24e9374"
}
],
"types": [
"ID"
]
}{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2"
],
"spl": "2020-09-01",
"vanir_signatures": [
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2",
"target": {
"file": "src/com/android/phone/EmergencyCallbackModeService.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"41947819677962889077519451532663704680",
"102135948322594920735190946348112074288",
"220160467030282996760638356047881540303",
"253889126629877657108515330408653953158",
"276112923747055330083233450457693907914"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "ASB-A-154124307-7ceae2e0"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2",
"target": {
"function": "showNotification",
"file": "src/com/android/phone/EmergencyCallbackModeService.java"
},
"deprecated": false,
"digest": {
"function_hash": "239929725198670433305970540035158012328",
"length": 1554.0
},
"signature_type": "Function",
"id": "ASB-A-154124307-b9ee0d90"
}
],
"types": [
"ID"
]
}{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7"
],
"spl": "2020-09-01",
"vanir_signatures": [
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7",
"target": {
"file": "src/java/com/android/internal/telephony/euicc/EuiccController.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"117644871708654916346245945015463275626",
"223665824716409487639496807541848082315",
"153896511408108601377244622035927833590",
"214338118115568385601977212861965221200",
"252555523724162323221182265734240667994",
"262626998732534039738096859923668305917",
"284733846293931103168905718368524179728",
"295496958192235468506319800338169638268",
"73099640744412732828548186330436131037",
"145124376558202810450310734881358587716",
"227614234266439378251246365778538648135"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "ASB-A-154124307-9ad82ed8"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7",
"target": {
"function": "addResolutionIntent",
"file": "src/java/com/android/internal/telephony/euicc/EuiccController.java"
},
"deprecated": false,
"digest": {
"function_hash": "124347352249865646556944936559596462054",
"length": 520.0
},
"signature_type": "Function",
"id": "ASB-A-154124307-a73ebb1c"
}
],
"types": [
"ID"
]
}{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2"
],
"spl": "2020-09-01",
"vanir_signatures": [
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2",
"target": {
"function": "showNotification",
"file": "src/com/android/phone/EmergencyCallbackModeService.java"
},
"deprecated": false,
"digest": {
"function_hash": "239929725198670433305970540035158012328",
"length": 1554.0
},
"signature_type": "Function",
"id": "ASB-A-154124307-1a42be31"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2",
"target": {
"file": "src/com/android/phone/EmergencyCallbackModeService.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"41947819677962889077519451532663704680",
"102135948322594920735190946348112074288",
"220160467030282996760638356047881540303",
"253889126629877657108515330408653953158",
"276112923747055330083233450457693907914"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "ASB-A-154124307-573e3292"
}
],
"types": [
"ID"
]
}{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7"
],
"spl": "2020-09-01",
"vanir_signatures": [
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7",
"target": {
"function": "addResolutionIntent",
"file": "src/java/com/android/internal/telephony/euicc/EuiccController.java"
},
"deprecated": false,
"digest": {
"function_hash": "124347352249865646556944936559596462054",
"length": 520.0
},
"signature_type": "Function",
"id": "ASB-A-154124307-2aa7e155"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7",
"target": {
"file": "src/java/com/android/internal/telephony/euicc/EuiccController.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"117644871708654916346245945015463275626",
"223665824716409487639496807541848082315",
"153896511408108601377244622035927833590",
"214338118115568385601977212861965221200",
"252555523724162323221182265734240667994",
"262626998732534039738096859923668305917",
"284733846293931103168905718368524179728",
"295496958192235468506319800338169638268",
"73099640744412732828548186330436131037",
"145124376558202810450310734881358587716",
"227614234266439378251246365778538648135"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "ASB-A-154124307-3f845299"
}
],
"types": [
"ID"
]
}{
"severity": "High",
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2"
],
"spl": "2020-09-01",
"vanir_signatures": [
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2",
"target": {
"file": "src/com/android/phone/EmergencyCallbackModeService.java"
},
"deprecated": false,
"digest": {
"line_hashes": [
"41947819677962889077519451532663704680",
"102135948322594920735190946348112074288",
"220160467030282996760638356047881540303",
"253889126629877657108515330408653953158",
"276112923747055330083233450457693907914"
],
"threshold": 0.9
},
"signature_type": "Line",
"id": "ASB-A-154124307-313eb20d"
},
{
"signature_version": "v1",
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2",
"target": {
"function": "showNotification",
"file": "src/com/android/phone/EmergencyCallbackModeService.java"
},
"deprecated": false,
"digest": {
"function_hash": "239929725198670433305970540035158012328",
"length": 1554.0
},
"signature_type": "Function",
"id": "ASB-A-154124307-aa484ca2"
}
],
"types": [
"ID"
]
}