ASB-A-289809991

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-289809991.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-289809991
Aliases
  • A-289809991
  • CVE-2023-40130
Published
2025-12-01T00:00:00Z
Modified
2026-01-23T16:22:14.675351Z
Summary
[none]
Details

In notifyTimeout of CallRedirectionProcessor, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege and background activity launch with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android

platform/packages/services/Telecomm

Package

Name
platform/packages/services/Telecomm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16-qpr2-next:0
Fixed
16-qpr2-next:2025-12-01

Affected versions

Other

16-qpr2-next

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/services/Telecomm/+/4a358cfd8e403597651a6962e8e43c11ea906a59",
        "https://android.googlesource.com/platform/packages/services/Telecomm/+/615a452b1eb9a1165b6892b715ca9acb39c9fc48"
    ],
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/615a452b1eb9a1165b6892b715ca9acb39c9fc48",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "133914857003413315646570965718557078818",
                    "315982243663284195210992618241822014595",
                    "266328628859364282669968728475815143824",
                    "9519643085536760170172263363297085188"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-289809991-5cef733f",
            "target": {
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/615a452b1eb9a1165b6892b715ca9acb39c9fc48",
            "deprecated": false,
            "digest": {
                "length": 474.0,
                "function_hash": "149316474348384160614910124841553593048"
            },
            "signature_type": "Function",
            "id": "ASB-A-289809991-923f8518",
            "target": {
                "function": "notifyTimeout",
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/4a358cfd8e403597651a6962e8e43c11ea906a59",
            "deprecated": false,
            "digest": {
                "length": 257.0,
                "function_hash": "191252294837772896851767483113381809875"
            },
            "signature_type": "Function",
            "id": "ASB-A-289809991-b32ef57f",
            "target": {
                "function": "notifyTimeout",
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/4a358cfd8e403597651a6962e8e43c11ea906a59",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "172429749700010611250441346059781583843",
                    "59903213920553620876219754985547236589",
                    "212799495587578912626871303567720377655",
                    "311277500521534153850202631705000053314"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-289809991-ff34cb91",
            "target": {
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        }
    ],
    "types": [
        "EoP"
    ],
    "severity": "High",
    "spl": "2025-12-01"
}

Database specific

source

"https://storage.googleapis.com/android-osv/ASB-A-289809991.json"

platform/packages/services/Telecomm

Package

Name
platform/packages/services/Telecomm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15:0
Fixed
15:2025-12-01

Affected versions

Other

15

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/services/Telecomm/+/12e18223ec4167fcedf44b18a8627c5651286451",
        "https://android.googlesource.com/platform/packages/services/Telecomm/+/e27f6e38b5677f9e82f485afded30e77d3d1c419"
    ],
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/12e18223ec4167fcedf44b18a8627c5651286451",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "172429749700010611250441346059781583843",
                    "59903213920553620876219754985547236589",
                    "212799495587578912626871303567720377655",
                    "311277500521534153850202631705000053314"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-289809991-97a50a6e",
            "target": {
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/12e18223ec4167fcedf44b18a8627c5651286451",
            "deprecated": false,
            "digest": {
                "length": 257.0,
                "function_hash": "191252294837772896851767483113381809875"
            },
            "signature_type": "Function",
            "id": "ASB-A-289809991-a9982ac6",
            "target": {
                "function": "notifyTimeout",
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/e27f6e38b5677f9e82f485afded30e77d3d1c419",
            "deprecated": false,
            "digest": {
                "length": 474.0,
                "function_hash": "149316474348384160614910124841553593048"
            },
            "signature_type": "Function",
            "id": "ASB-A-289809991-e10b2ab2",
            "target": {
                "function": "notifyTimeout",
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/e27f6e38b5677f9e82f485afded30e77d3d1c419",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "133914857003413315646570965718557078818",
                    "315982243663284195210992618241822014595",
                    "266328628859364282669968728475815143824",
                    "9519643085536760170172263363297085188"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-289809991-fdbccc0c",
            "target": {
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        }
    ],
    "types": [
        "EoP"
    ],
    "severity": "High",
    "spl": "2025-12-01"
}

Database specific

source

"https://storage.googleapis.com/android-osv/ASB-A-289809991.json"

platform/packages/services/Telecomm

Package

Name
platform/packages/services/Telecomm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16:0
Fixed
16:2025-12-01

Affected versions

Other

16

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/services/Telecomm/+/f789378f13380ec741141ec203663248b1734c0f"
    ],
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/f789378f13380ec741141ec203663248b1734c0f",
            "deprecated": false,
            "digest": {
                "length": 474.0,
                "function_hash": "149316474348384160614910124841553593048"
            },
            "signature_type": "Function",
            "id": "ASB-A-289809991-058e7e1e",
            "target": {
                "function": "notifyTimeout",
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/f789378f13380ec741141ec203663248b1734c0f",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "133914857003413315646570965718557078818",
                    "315982243663284195210992618241822014595",
                    "266328628859364282669968728475815143824",
                    "9519643085536760170172263363297085188"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-289809991-6306745a",
            "target": {
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        }
    ],
    "types": [
        "EoP"
    ],
    "severity": "High",
    "spl": "2025-12-01"
}

Database specific

source

"https://storage.googleapis.com/android-osv/ASB-A-289809991.json"

platform/packages/services/Telecomm

Package

Name
platform/packages/services/Telecomm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13:0
Fixed
13:2025-12-01

Affected versions

Other

13

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/services/Telecomm/+/425b355b0e845595c0e1d698ff2f533a46f58830",
        "https://android.googlesource.com/platform/packages/services/Telecomm/+/202392eba2a1d04a135272efe816efdb7182eb62"
    ],
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/202392eba2a1d04a135272efe816efdb7182eb62",
            "deprecated": false,
            "digest": {
                "length": 474.0,
                "function_hash": "149316474348384160614910124841553593048"
            },
            "signature_type": "Function",
            "id": "ASB-A-289809991-1ee25ee0",
            "target": {
                "function": "notifyTimeout",
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/425b355b0e845595c0e1d698ff2f533a46f58830",
            "deprecated": false,
            "digest": {
                "length": 257.0,
                "function_hash": "191252294837772896851767483113381809875"
            },
            "signature_type": "Function",
            "id": "ASB-A-289809991-2d98bdc4",
            "target": {
                "function": "notifyTimeout",
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/202392eba2a1d04a135272efe816efdb7182eb62",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "133914857003413315646570965718557078818",
                    "315982243663284195210992618241822014595",
                    "266328628859364282669968728475815143824",
                    "9519643085536760170172263363297085188"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-289809991-7e165845",
            "target": {
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/425b355b0e845595c0e1d698ff2f533a46f58830",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "172429749700010611250441346059781583843",
                    "59903213920553620876219754985547236589",
                    "212799495587578912626871303567720377655",
                    "311277500521534153850202631705000053314"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-289809991-fc703e84",
            "target": {
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        }
    ],
    "types": [
        "EoP"
    ],
    "severity": "High",
    "spl": "2025-12-01"
}

Database specific

source

"https://storage.googleapis.com/android-osv/ASB-A-289809991.json"

platform/packages/services/Telecomm

Package

Name
platform/packages/services/Telecomm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14:0
Fixed
14:2025-12-01

Affected versions

Other

14

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/packages/services/Telecomm/+/9733de498bc44d9865b0061564ac3344426f4da9",
        "https://android.googlesource.com/platform/packages/services/Telecomm/+/fa832b0e972b1f5058c2028384fa231478aa4ff2"
    ],
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/9733de498bc44d9865b0061564ac3344426f4da9",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "172429749700010611250441346059781583843",
                    "59903213920553620876219754985547236589",
                    "212799495587578912626871303567720377655",
                    "311277500521534153850202631705000053314"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-289809991-34758aa2",
            "target": {
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/fa832b0e972b1f5058c2028384fa231478aa4ff2",
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "133914857003413315646570965718557078818",
                    "315982243663284195210992618241822014595",
                    "266328628859364282669968728475815143824",
                    "9519643085536760170172263363297085188"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-289809991-418550f6",
            "target": {
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/9733de498bc44d9865b0061564ac3344426f4da9",
            "deprecated": false,
            "digest": {
                "length": 257.0,
                "function_hash": "191252294837772896851767483113381809875"
            },
            "signature_type": "Function",
            "id": "ASB-A-289809991-5e23de8a",
            "target": {
                "function": "notifyTimeout",
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/fa832b0e972b1f5058c2028384fa231478aa4ff2",
            "deprecated": false,
            "digest": {
                "length": 474.0,
                "function_hash": "149316474348384160614910124841553593048"
            },
            "signature_type": "Function",
            "id": "ASB-A-289809991-e2982aaf",
            "target": {
                "function": "notifyTimeout",
                "file": "src/com/android/server/telecom/callredirection/CallRedirectionProcessor.java"
            }
        }
    ],
    "types": [
        "EoP"
    ],
    "severity": "High",
    "spl": "2025-12-01"
}

Database specific

source

"https://storage.googleapis.com/android-osv/ASB-A-289809991.json"