In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"106680201593422794262120843882354478791",
"326774004061573496066568127664103587028",
"295395256957196504913463328355904672893",
"149183730702223882063009548301812832852",
"111530533399569871322797409736703837069",
"164450686893749293223111827008859727071",
"72195964722680638204432878196194950937",
"172334718998239283189666931642852725078"
]
},
"id": "ASB-A-185126319-2f5d2b96",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b",
"target": {
"file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java"
}
},
{
"digest": {
"length": 1385.0,
"function_hash": "242911685893440700542492214997579498592"
},
"id": "ASB-A-185126319-c19e1d43",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b",
"target": {
"function": "sendLegacyVoicemailNotification",
"file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b"
],
"types": [
"EoP"
],
"spl": "2022-01-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"106680201593422794262120843882354478791",
"326774004061573496066568127664103587028",
"295395256957196504913463328355904672893",
"149183730702223882063009548301812832852",
"111530533399569871322797409736703837069",
"164450686893749293223111827008859727071",
"72195964722680638204432878196194950937",
"172334718998239283189666931642852725078"
]
},
"id": "ASB-A-185126319-47c021ac",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b",
"target": {
"file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java"
}
},
{
"digest": {
"length": 1385.0,
"function_hash": "242911685893440700542492214997579498592"
},
"id": "ASB-A-185126319-6c87a72c",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b",
"target": {
"function": "sendLegacyVoicemailNotification",
"file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b"
],
"types": [
"EoP"
],
"spl": "2022-01-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"106680201593422794262120843882354478791",
"326774004061573496066568127664103587028",
"295395256957196504913463328355904672893",
"149183730702223882063009548301812832852",
"111530533399569871322797409736703837069",
"164450686893749293223111827008859727071",
"72195964722680638204432878196194950937",
"172334718998239283189666931642852725078"
]
},
"id": "ASB-A-185126319-c7359f3d",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b",
"target": {
"file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java"
}
},
{
"digest": {
"length": 1385.0,
"function_hash": "242911685893440700542492214997579498592"
},
"id": "ASB-A-185126319-f4f18912",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b",
"target": {
"function": "sendLegacyVoicemailNotification",
"file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b"
],
"types": [
"EoP"
],
"spl": "2022-01-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"106680201593422794262120843882354478791",
"326774004061573496066568127664103587028",
"295395256957196504913463328355904672893",
"149183730702223882063009548301812832852",
"111530533399569871322797409736703837069",
"164450686893749293223111827008859727071",
"72195964722680638204432878196194950937",
"172334718998239283189666931642852725078"
]
},
"id": "ASB-A-185126319-7d5c7dd5",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b",
"target": {
"file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java"
}
},
{
"digest": {
"length": 1385.0,
"function_hash": "242911685893440700542492214997579498592"
},
"id": "ASB-A-185126319-fc45b3ca",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b",
"target": {
"function": "sendLegacyVoicemailNotification",
"file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b"
],
"types": [
"EoP"
],
"spl": "2022-01-01",
"severity": "High"
}