In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"322179152667443566213635062152586210488",
"302154512749291372025215128589189914285",
"79769725206224791662607660065147568683",
"157305871852941368301729444261912684793",
"44712258134504983053774453234221765831",
"140395474102336232780420469452333842497",
"67982921254483870507642281109402768204",
"300238249256955079666881244971898924305",
"165298622424173680646359658852840888207",
"114271158995927676688427381791986637864",
"50708410894798798326959356230949396476",
"200419992510259407468683780180144744000"
]
},
"id": "ASB-A-185235454-088a1593",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/1996daaf750f417e27888a0fb8656330371241fc",
"target": {
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
},
{
"digest": {
"length": 884.0,
"function_hash": "194429974815737595204872300169648639657"
},
"id": "ASB-A-185235454-fc86d38f",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/1996daaf750f417e27888a0fb8656330371241fc",
"target": {
"function": "getAvailableSubscriptionInfoList",
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/1996daaf750f417e27888a0fb8656330371241fc"
],
"types": [
"ID"
],
"spl": "2021-08-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 966.0,
"function_hash": "10834130118716387980513045232405040831"
},
"id": "ASB-A-185235454-21ff6665",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/2d01df99deba66fbdac7ca1a678a955c64c5318f",
"target": {
"function": "getAvailableSubscriptionInfoList",
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"322179152667443566213635062152586210488",
"302154512749291372025215128589189914285",
"79769725206224791662607660065147568683",
"157305871852941368301729444261912684793",
"44712258134504983053774453234221765831",
"140395474102336232780420469452333842497",
"67982921254483870507642281109402768204",
"317179960651733581027699211625528187844",
"137001379270367974367826692771061504278",
"207722426495214467888271829540402290979",
"186101170189287384730125460759207797391",
"263819795159073480990744039293080800974",
"248760339125170916730817611748457394144",
"200419992510259407468683780180144744000"
]
},
"id": "ASB-A-185235454-bef4f3db",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/2d01df99deba66fbdac7ca1a678a955c64c5318f",
"target": {
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/2d01df99deba66fbdac7ca1a678a955c64c5318f"
],
"types": [
"ID"
],
"spl": "2021-08-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 995.0,
"function_hash": "295565763983439835740416590784161204844"
},
"id": "ASB-A-185235454-2b01d40c",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/dd0a8f8c5332e9ebcc983951e01ec3c7983188c7",
"target": {
"function": "getAvailableSubscriptionInfoList",
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"308083939548892577897224080200540255444",
"214562141067841948983412341100333928522",
"160738874635641536349344562415977389651",
"44861382247902900182343580197047170298",
"317179960651733581027699211625528187844",
"137001379270367974367826692771061504278",
"207722426495214467888271829540402290979",
"186101170189287384730125460759207797391",
"263819795159073480990744039293080800974",
"248760339125170916730817611748457394144",
"200419992510259407468683780180144744000"
]
},
"id": "ASB-A-185235454-a1ed1c38",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/dd0a8f8c5332e9ebcc983951e01ec3c7983188c7",
"target": {
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/dd0a8f8c5332e9ebcc983951e01ec3c7983188c7"
],
"types": [
"ID"
],
"spl": "2021-08-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 1149.0,
"function_hash": "94819161903269189739373646259786815365"
},
"id": "ASB-A-185235454-37f617b1",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/9f741b9a3f871cde331f0c0f06abaa42e74f87f8",
"target": {
"function": "getAvailableSubscriptionInfoList",
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"308083939548892577897224080200540255444",
"214562141067841948983412341100333928522",
"160738874635641536349344562415977389651",
"44861382247902900182343580197047170298",
"291210842795300834745212578741290321273",
"3057374561742708349612180504265935563",
"272211894748714570887657777387157996278",
"171993590426064100538565987468376097400",
"208078310247559336231525144375592506295",
"252760015762893403940434711916388917966",
"200419992510259407468683780180144744000"
]
},
"id": "ASB-A-185235454-f541d2b3",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/9f741b9a3f871cde331f0c0f06abaa42e74f87f8",
"target": {
"file": "src/java/com/android/internal/telephony/SubscriptionController.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/opt/telephony/+/9f741b9a3f871cde331f0c0f06abaa42e74f87f8"
],
"types": [
"ID"
],
"spl": "2021-08-01",
"severity": "High"
}