In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"100326431459558569292119600264389787165",
"224460809244113809053494007357703622319",
"333762841701727134505390074716578964885",
"199218706011219857461499847670488384710",
"19256926819814878956514261880855948330",
"139717360613838074749875733557269753678",
"183664305217219171351514465603028527937",
"139804455583322841000522678523842891823"
]
},
"id": "ASB-A-329058967-81dba51d",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/8c619f58c00047ab0ec687cd231bf93a08db6d55",
"target": {
"file": "src/com/android/server/telecom/ConnectionServiceWrapper.java"
}
},
{
"digest": {
"length": 967.0,
"function_hash": "95813100806952752517657637119407566504"
},
"id": "ASB-A-329058967-db818686",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/8c619f58c00047ab0ec687cd231bf93a08db6d55",
"target": {
"function": "handleCreateConferenceComplete",
"file": "src/com/android/server/telecom/ConnectionServiceWrapper.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/8c619f58c00047ab0ec687cd231bf93a08db6d55"
],
"types": [
"ID"
],
"spl": "2024-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"100326431459558569292119600264389787165",
"224460809244113809053494007357703622319",
"333762841701727134505390074716578964885",
"199218706011219857461499847670488384710",
"19256926819814878956514261880855948330",
"139717360613838074749875733557269753678",
"183664305217219171351514465603028527937",
"139804455583322841000522678523842891823"
]
},
"id": "ASB-A-329058967-0fe4a2cb",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802",
"target": {
"file": "src/com/android/server/telecom/ConnectionServiceWrapper.java"
}
},
{
"digest": {
"length": 967.0,
"function_hash": "95813100806952752517657637119407566504"
},
"id": "ASB-A-329058967-d51dfc42",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802",
"target": {
"function": "handleCreateConferenceComplete",
"file": "src/com/android/server/telecom/ConnectionServiceWrapper.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802"
],
"types": [
"ID"
],
"spl": "2024-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"length": 967.0,
"function_hash": "95813100806952752517657637119407566504"
},
"id": "ASB-A-329058967-2f17c47d",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802",
"target": {
"function": "handleCreateConferenceComplete",
"file": "src/com/android/server/telecom/ConnectionServiceWrapper.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"100326431459558569292119600264389787165",
"224460809244113809053494007357703622319",
"333762841701727134505390074716578964885",
"199218706011219857461499847670488384710",
"19256926819814878956514261880855948330",
"139717360613838074749875733557269753678",
"183664305217219171351514465603028527937",
"139804455583322841000522678523842891823"
]
},
"id": "ASB-A-329058967-7d2c5330",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802",
"target": {
"file": "src/com/android/server/telecom/ConnectionServiceWrapper.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802"
],
"types": [
"ID"
],
"spl": "2024-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"100326431459558569292119600264389787165",
"224460809244113809053494007357703622319",
"333762841701727134505390074716578964885",
"199218706011219857461499847670488384710",
"19256926819814878956514261880855948330",
"139717360613838074749875733557269753678",
"183664305217219171351514465603028527937",
"139804455583322841000522678523842891823"
]
},
"id": "ASB-A-329058967-ca84df39",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802",
"target": {
"file": "src/com/android/server/telecom/ConnectionServiceWrapper.java"
}
},
{
"digest": {
"length": 967.0,
"function_hash": "95813100806952752517657637119407566504"
},
"id": "ASB-A-329058967-ff959e01",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802",
"target": {
"function": "handleCreateConferenceComplete",
"file": "src/com/android/server/telecom/ConnectionServiceWrapper.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802"
],
"types": [
"ID"
],
"spl": "2024-09-01",
"severity": "High"
}{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"100326431459558569292119600264389787165",
"224460809244113809053494007357703622319",
"333762841701727134505390074716578964885",
"199218706011219857461499847670488384710",
"19256926819814878956514261880855948330",
"139717360613838074749875733557269753678",
"183664305217219171351514465603028527937",
"139804455583322841000522678523842891823"
]
},
"id": "ASB-A-329058967-1639fb22",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802",
"target": {
"file": "src/com/android/server/telecom/ConnectionServiceWrapper.java"
}
},
{
"digest": {
"length": 967.0,
"function_hash": "95813100806952752517657637119407566504"
},
"id": "ASB-A-329058967-798c60b6",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802",
"target": {
"function": "handleCreateConferenceComplete",
"file": "src/com/android/server/telecom/ConnectionServiceWrapper.java"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telecomm/+/a8e2bf9c77cd94f683979c849015b78ef0537802"
],
"types": [
"ID"
],
"spl": "2024-09-01",
"severity": "High"
}