In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"90318205065606561043884690310810845677",
"136994689380649245360518211420121968453",
"298740314377000020502263473144852808838",
"21387850157299654266101515218898453776",
"250733354817558946597434227752831285804",
"323029196704237783690810370671001093584",
"56609536568271248166245200469451222536",
"70617805874188584440178893864371025281",
"145050397850970283445092671007393099435",
"325460288744236392637473733485734496931",
"120554692771712425450164883798148210965",
"216753325627485995622306550072138495563",
"310419024130454413646494475091772126323",
"128375389671755078266861537160023294952",
"163232583368852320667111453582922645589",
"14284280858149685098989265174006597933",
"17569772172361472032489349891596062196",
"309870465881777670000889058642353937880",
"202637388650123876466385843878974427368",
"186030785590081878932242815522794011201",
"130567286403321222431699522616763289847"
]
},
"id": "ASB-A-235098883-19ab49e4",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/d80cf1a7b71119e6843f2ee3e43f8c49f6bf3f54",
"target": {
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 3306.0,
"function_hash": "241754292414573096411305693026388168696"
},
"id": "ASB-A-235098883-1a1613ed",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/d80cf1a7b71119e6843f2ee3e43f8c49f6bf3f54",
"target": {
"function": "onCallRedirectionComplete",
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 129.0,
"function_hash": "136016856945005241622357145227811723443"
},
"id": "ASB-A-235098883-433742f4",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/d80cf1a7b71119e6843f2ee3e43f8c49f6bf3f54",
"target": {
"function": "loggedRun",
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 211.0,
"function_hash": "56996565309622859199760986891345043267"
},
"id": "ASB-A-235098883-fd875d89",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/d80cf1a7b71119e6843f2ee3e43f8c49f6bf3f54",
"target": {
"function": "loggedRun",
"file": "src/com/android/server/telecom/CallsManager.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/d80cf1a7b71119e6843f2ee3e43f8c49f6bf3f54"
],
"types": [
"EoP"
],
"spl": "2022-11-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 3013.0,
"function_hash": "182971787671837446836215734929938011431"
},
"id": "ASB-A-235098883-286bf0d5",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/256ef21f54f70e5b3d32058806ceeff546d7e07a",
"target": {
"function": "onCallRedirectionComplete",
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"90318205065606561043884690310810845677",
"5796137444434912928138706482082313920",
"49476044142096104189746131419820537579",
"126291089231107155096707050100944468383",
"250733354817558946597434227752831285804",
"323029196704237783690810370671001093584",
"56609536568271248166245200469451222536",
"246107628532541466110725314629604045334",
"75637455373044755721658173082363347420",
"183612808229199593950615287424797619157",
"120554692771712425450164883798148210965",
"216753325627485995622306550072138495563",
"310419024130454413646494475091772126323",
"128375389671755078266861537160023294952",
"163232583368852320667111453582922645589",
"14284280858149685098989265174006597933",
"17569772172361472032489349891596062196",
"309870465881777670000889058642353937880",
"202637388650123876466385843878974427368",
"186030785590081878932242815522794011201",
"130567286403321222431699522616763289847"
]
},
"id": "ASB-A-235098883-a7588d8b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/256ef21f54f70e5b3d32058806ceeff546d7e07a",
"target": {
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 211.0,
"function_hash": "56996565309622859199760986891345043267"
},
"id": "ASB-A-235098883-c0b32164",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/256ef21f54f70e5b3d32058806ceeff546d7e07a",
"target": {
"function": "loggedRun",
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 129.0,
"function_hash": "136016856945005241622357145227811723443"
},
"id": "ASB-A-235098883-e8aa6a17",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/256ef21f54f70e5b3d32058806ceeff546d7e07a",
"target": {
"function": "loggedRun",
"file": "src/com/android/server/telecom/CallsManager.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/256ef21f54f70e5b3d32058806ceeff546d7e07a"
],
"types": [
"EoP"
],
"spl": "2022-11-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 3065.0,
"function_hash": "304563262180663244574201306052709331678"
},
"id": "ASB-A-235098883-53a23ec8",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/6b0e9b46adcb7af1fcc19a92fc887e1b6ee19921",
"target": {
"function": "onCallRedirectionComplete",
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"90318205065606561043884690310810845677",
"5796137444434912928138706482082313920",
"49476044142096104189746131419820537579",
"126291089231107155096707050100944468383",
"250733354817558946597434227752831285804",
"323029196704237783690810370671001093584",
"56609536568271248166245200469451222536",
"246107628532541466110725314629604045334",
"75637455373044755721658173082363347420",
"183612808229199593950615287424797619157",
"120554692771712425450164883798148210965",
"216753325627485995622306550072138495563",
"310419024130454413646494475091772126323",
"128375389671755078266861537160023294952",
"163232583368852320667111453582922645589",
"14284280858149685098989265174006597933",
"17569772172361472032489349891596062196",
"309870465881777670000889058642353937880",
"202637388650123876466385843878974427368",
"186030785590081878932242815522794011201",
"130567286403321222431699522616763289847"
]
},
"id": "ASB-A-235098883-851a327c",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/6b0e9b46adcb7af1fcc19a92fc887e1b6ee19921",
"target": {
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 129.0,
"function_hash": "136016856945005241622357145227811723443"
},
"id": "ASB-A-235098883-9ac7a66d",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/6b0e9b46adcb7af1fcc19a92fc887e1b6ee19921",
"target": {
"function": "loggedRun",
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 211.0,
"function_hash": "56996565309622859199760986891345043267"
},
"id": "ASB-A-235098883-aa4e4e13",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/6b0e9b46adcb7af1fcc19a92fc887e1b6ee19921",
"target": {
"function": "loggedRun",
"file": "src/com/android/server/telecom/CallsManager.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/6b0e9b46adcb7af1fcc19a92fc887e1b6ee19921"
],
"types": [
"EoP"
],
"spl": "2022-11-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 3065.0,
"function_hash": "304563262180663244574201306052709331678"
},
"id": "ASB-A-235098883-61ff9f53",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/735b84a90e5305915836329d4abca672fcc87126",
"target": {
"function": "onCallRedirectionComplete",
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 129.0,
"function_hash": "136016856945005241622357145227811723443"
},
"id": "ASB-A-235098883-6cbe5bc8",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/735b84a90e5305915836329d4abca672fcc87126",
"target": {
"function": "loggedRun",
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"90318205065606561043884690310810845677",
"5796137444434912928138706482082313920",
"49476044142096104189746131419820537579",
"126291089231107155096707050100944468383",
"250733354817558946597434227752831285804",
"323029196704237783690810370671001093584",
"56609536568271248166245200469451222536",
"246107628532541466110725314629604045334",
"75637455373044755721658173082363347420",
"183612808229199593950615287424797619157",
"120554692771712425450164883798148210965",
"216753325627485995622306550072138495563",
"310419024130454413646494475091772126323",
"128375389671755078266861537160023294952",
"163232583368852320667111453582922645589",
"14284280858149685098989265174006597933",
"17569772172361472032489349891596062196",
"309870465881777670000889058642353937880",
"202637388650123876466385843878974427368",
"186030785590081878932242815522794011201",
"130567286403321222431699522616763289847"
]
},
"id": "ASB-A-235098883-874a75b4",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/735b84a90e5305915836329d4abca672fcc87126",
"target": {
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 211.0,
"function_hash": "56996565309622859199760986891345043267"
},
"id": "ASB-A-235098883-db64cde6",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/735b84a90e5305915836329d4abca672fcc87126",
"target": {
"function": "loggedRun",
"file": "src/com/android/server/telecom/CallsManager.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/735b84a90e5305915836329d4abca672fcc87126"
],
"types": [
"EoP"
],
"spl": "2022-11-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 211.0,
"function_hash": "56996565309622859199760986891345043267"
},
"id": "ASB-A-235098883-46317b98",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/735b84a90e5305915836329d4abca672fcc87126",
"target": {
"function": "loggedRun",
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"90318205065606561043884690310810845677",
"5796137444434912928138706482082313920",
"49476044142096104189746131419820537579",
"126291089231107155096707050100944468383",
"250733354817558946597434227752831285804",
"323029196704237783690810370671001093584",
"56609536568271248166245200469451222536",
"246107628532541466110725314629604045334",
"75637455373044755721658173082363347420",
"183612808229199593950615287424797619157",
"120554692771712425450164883798148210965",
"216753325627485995622306550072138495563",
"310419024130454413646494475091772126323",
"128375389671755078266861537160023294952",
"163232583368852320667111453582922645589",
"14284280858149685098989265174006597933",
"17569772172361472032489349891596062196",
"309870465881777670000889058642353937880",
"202637388650123876466385843878974427368",
"186030785590081878932242815522794011201",
"130567286403321222431699522616763289847"
]
},
"id": "ASB-A-235098883-5504693d",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/735b84a90e5305915836329d4abca672fcc87126",
"target": {
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 3065.0,
"function_hash": "304563262180663244574201306052709331678"
},
"id": "ASB-A-235098883-89c09440",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/735b84a90e5305915836329d4abca672fcc87126",
"target": {
"function": "onCallRedirectionComplete",
"file": "src/com/android/server/telecom/CallsManager.java"
}
},
{
"digest": {
"length": 129.0,
"function_hash": "136016856945005241622357145227811723443"
},
"id": "ASB-A-235098883-e2817f25",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/735b84a90e5305915836329d4abca672fcc87126",
"target": {
"function": "loggedRun",
"file": "src/com/android/server/telecom/CallsManager.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/735b84a90e5305915836329d4abca672fcc87126"
],
"types": [
"EoP"
],
"spl": "2022-11-01",
"severity": "High"
}