In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"149314389111778334465882658059004023231",
"193741661406318947171187996572299546511",
"86997667788922410104420909344407444020"
]
},
"id": "ASB-A-181053462-d3a44dd9",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/873d4bffb26cf2673ddfa949928186c7c99dd564",
"target": {
"file": "telephony/java/android/telephony/SubscriptionInfo.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/873d4bffb26cf2673ddfa949928186c7c99dd564"
],
"types": [
"ID"
],
"spl": "2021-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"73058060908721465202703923844009171842",
"106761157209031659183026918433137740754",
"166020037415362058612189230784165644485",
"287162283271674705512625053057635952635"
]
},
"id": "ASB-A-181053462-686f38c2",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/7264df380483454f0e24c5028df129d58d41390a",
"target": {
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
},
{
"digest": {
"length": 188.0,
"function_hash": "19943514698718854185069749005214643415"
},
"id": "ASB-A-181053462-a39429d7",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/7264df380483454f0e24c5028df129d58d41390a",
"target": {
"function": "conditionallyRemoveIdentifiers",
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/7264df380483454f0e24c5028df129d58d41390a"
],
"types": [
"ID"
],
"spl": "2021-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"149314389111778334465882658059004023231",
"193741661406318947171187996572299546511",
"86997667788922410104420909344407444020"
]
},
"id": "ASB-A-181053462-10eaf862",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/121c969e22950cd966bb99b101c1e7e50084ae3c",
"target": {
"file": "telephony/java/android/telephony/SubscriptionInfo.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/121c969e22950cd966bb99b101c1e7e50084ae3c"
],
"types": [
"ID"
],
"spl": "2021-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 251.0,
"function_hash": "59640212500690590811746554702991855553"
},
"id": "ASB-A-181053462-601c01dd",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/1399361f2e553a673b4a0d90131c44ee2fe0e32a",
"target": {
"function": "conditionallyRemoveIdentifiers",
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"73058060908721465202703923844009171842",
"106761157209031659183026918433137740754",
"336981098826025419991630921647913478704",
"248274745367760804006245785737486142426"
]
},
"id": "ASB-A-181053462-65a6f1ca",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/1399361f2e553a673b4a0d90131c44ee2fe0e32a",
"target": {
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/1399361f2e553a673b4a0d90131c44ee2fe0e32a"
],
"types": [
"ID"
],
"spl": "2021-09-01",
"severity": "High"
}