In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"length": 1589.0,
"function_hash": "267014055218915562324544224807642477596"
},
"id": "ASB-A-177238342-21ed1dfc",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/7fe88ee4d21df9715d1326995ef9f1160945f8a7",
"target": {
"function": "processInboundMessage",
"file": "src/com/android/bluetooth/mapclient/MceStateMachine.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"204567973715472067066247483845272490480",
"4651904736654534218624381003266123619",
"175106579451678976287564149135052824973",
"50516183646675268844942920109146207064",
"239927787402054502068805163281703011302",
"118578066003825052603890285099994597954",
"280191191649882434054280314678359611874",
"17024649308917103928626280810893798588"
]
},
"id": "ASB-A-177238342-b2941ee4",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/7fe88ee4d21df9715d1326995ef9f1160945f8a7",
"target": {
"file": "src/com/android/bluetooth/mapclient/MceStateMachine.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Bluetooth/+/7fe88ee4d21df9715d1326995ef9f1160945f8a7"
],
"types": [
"ID"
],
"spl": "2021-07-01",
"severity": "High"
}
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"88242695581226210517726882826385907342",
"228351318621997576290397813409176551539",
"306990524383001794509029399546078534620",
"30870753740782282268746949493014393146",
"239927787402054502068805163281703011302",
"118578066003825052603890285099994597954",
"280191191649882434054280314678359611874",
"17024649308917103928626280810893798588"
]
},
"id": "ASB-A-177238342-256d90e9",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/1053a248da167ab586e282fb8057fef2ef87b659",
"target": {
"file": "src/com/android/bluetooth/mapclient/MceStateMachine.java"
}
},
{
"digest": {
"length": 1617.0,
"function_hash": "262941306501579972416702905455252343848"
},
"id": "ASB-A-177238342-ede25644",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Bluetooth/+/1053a248da167ab586e282fb8057fef2ef87b659",
"target": {
"function": "processInboundMessage",
"file": "src/com/android/bluetooth/mapclient/MceStateMachine.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Bluetooth/+/1053a248da167ab586e282fb8057fef2ef87b659"
],
"types": [
"ID"
],
"spl": "2021-07-01",
"severity": "High"
}