In getNumberFromCallIntent of NewOutgoingCallIntentBroadcaster.java, there is a possible way to enumerate other user's contact phone number due to a confused deputy. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"length": 441.0,
"function_hash": "25650367202118149377194985008445113167"
},
"id": "ASB-A-257030107-4ffd9e2e",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/8e68d38e7c19316616be56a32d529e304ca5f964",
"target": {
"function": "getNumberFromCallIntent",
"file": "src/com/android/server/telecom/NewOutgoingCallIntentBroadcaster.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327619331133315666563816080453806279531",
"32318420182758874816211085765289972831",
"110281608545597591164431212138094532539",
"205695334337411931340614792260803245969",
"337691025631713075387907201661943463651"
]
},
"id": "ASB-A-257030107-cfe5498b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/8e68d38e7c19316616be56a32d529e304ca5f964",
"target": {
"file": "src/com/android/server/telecom/NewOutgoingCallIntentBroadcaster.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/8e68d38e7c19316616be56a32d529e304ca5f964"
],
"types": [
"ID"
],
"spl": "2023-04-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327619331133315666563816080453806279531",
"32318420182758874816211085765289972831",
"110281608545597591164431212138094532539",
"205695334337411931340614792260803245969",
"337691025631713075387907201661943463651"
]
},
"id": "ASB-A-257030107-25fd71ec",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/9636518478fb887dd1834c0433eb3a71eb72faaf",
"target": {
"file": "src/com/android/server/telecom/NewOutgoingCallIntentBroadcaster.java"
}
},
{
"digest": {
"length": 441.0,
"function_hash": "25650367202118149377194985008445113167"
},
"id": "ASB-A-257030107-e3a85c8c",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/9636518478fb887dd1834c0433eb3a71eb72faaf",
"target": {
"function": "getNumberFromCallIntent",
"file": "src/com/android/server/telecom/NewOutgoingCallIntentBroadcaster.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/9636518478fb887dd1834c0433eb3a71eb72faaf"
],
"types": [
"ID"
],
"spl": "2023-04-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 441.0,
"function_hash": "25650367202118149377194985008445113167"
},
"id": "ASB-A-257030107-425f4601",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/298e4ced68ac9a4b32ac4b0d2c872f0458033038",
"target": {
"function": "getNumberFromCallIntent",
"file": "src/com/android/server/telecom/NewOutgoingCallIntentBroadcaster.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327619331133315666563816080453806279531",
"32318420182758874816211085765289972831",
"110281608545597591164431212138094532539",
"205695334337411931340614792260803245969",
"337691025631713075387907201661943463651"
]
},
"id": "ASB-A-257030107-5fc5ac0c",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/298e4ced68ac9a4b32ac4b0d2c872f0458033038",
"target": {
"file": "src/com/android/server/telecom/NewOutgoingCallIntentBroadcaster.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/298e4ced68ac9a4b32ac4b0d2c872f0458033038"
],
"types": [
"ID"
],
"spl": "2023-04-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327619331133315666563816080453806279531",
"32318420182758874816211085765289972831",
"110281608545597591164431212138094532539",
"205695334337411931340614792260803245969",
"337691025631713075387907201661943463651"
]
},
"id": "ASB-A-257030107-4959307f",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/7bd3707b732d30be513cd98a91d4fb6857f3fba0",
"target": {
"file": "src/com/android/server/telecom/NewOutgoingCallIntentBroadcaster.java"
}
},
{
"digest": {
"length": 441.0,
"function_hash": "25650367202118149377194985008445113167"
},
"id": "ASB-A-257030107-cd06d5b9",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/7bd3707b732d30be513cd98a91d4fb6857f3fba0",
"target": {
"function": "getNumberFromCallIntent",
"file": "src/com/android/server/telecom/NewOutgoingCallIntentBroadcaster.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/7bd3707b732d30be513cd98a91d4fb6857f3fba0"
],
"types": [
"ID"
],
"spl": "2023-04-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 441.0,
"function_hash": "25650367202118149377194985008445113167"
},
"id": "ASB-A-257030107-20a54918",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/12073ab45493ad1018ee55334733cfa41e5df4f1",
"target": {
"function": "getNumberFromCallIntent",
"file": "src/com/android/server/telecom/NewOutgoingCallIntentBroadcaster.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"327619331133315666563816080453806279531",
"32318420182758874816211085765289972831",
"110281608545597591164431212138094532539",
"205695334337411931340614792260803245969",
"337691025631713075387907201661943463651"
]
},
"id": "ASB-A-257030107-311e5964",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/12073ab45493ad1018ee55334733cfa41e5df4f1",
"target": {
"file": "src/com/android/server/telecom/NewOutgoingCallIntentBroadcaster.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/12073ab45493ad1018ee55334733cfa41e5df4f1"
],
"types": [
"ID"
],
"spl": "2023-04-01",
"severity": "High"
}