In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "match_only_versions": [ "13" ], "digest": { "length": 1407.0, "function_hash": "22422532387122491668667721950104656157" }, "id": "PUB-A-224769956-33afdf62", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsSmsProvider.java", "function": "getMessagesByPhoneNumber" }, "signature_type": "Function" }, { "match_only_versions": [ "13" ], "digest": { "threshold": 0.9, "line_hashes": [ "258934897897631415745520717000714098069", "197014184272332667846658434605393915898", "246664981731303886033131157814483634983", "101001494901914073283465168712290708531", "40781936514460825829631966867885287527", "74775515332393555247263924237908194486", "71228892074586123301732053782579261311", "105011803168551978084127322986875381163", "137265764517892057556664940942374249360", "96700296200703501421605498402110971047", "204863617846661698942456037915140423870", "252949432377023224110765175983327207907", "277647244589725688428892329248863886364", "306605336572531699012372318475898263443", "169838437779391581360466352827228668039", "316756949732311853477928376052124049665", "76444377936777127146241846239546812827", "12758008060783028391415423680115144311", "151384020286346887885906492235622483531" ] }, "id": "PUB-A-224769956-63b4c4c4", "source": "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/providers/telephony/MmsSmsProvider.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f" ], "spl": "2022-12-01", "severity": "Moderate", "types": [ "ID" ] }