In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/7f6575528f222e6b56b51ed07a02a53ca9b65ec9",
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "src/com/android/phone/PhoneInterfaceManager.java"
},
"id": "PUB-A-229742768-974bc603",
"match_only_versions": [
"13"
],
"digest": {
"threshold": 0.9,
"line_hashes": [
"196627389734480781337006352051271306718",
"176199336712474822964219730830404357951",
"100018591607891501078266815945128062618",
"283347072164868859287192497592244016897",
"212212967777264311339447439895338260217"
]
}
},
{
"source": "https://android.googlesource.com/platform/packages/services/Telephony/+/7f6575528f222e6b56b51ed07a02a53ca9b65ec9",
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"target": {
"function": "enforceVisualVoicemailPackage",
"file": "src/com/android/phone/PhoneInterfaceManager.java"
},
"id": "PUB-A-229742768-f6fac92b",
"match_only_versions": [
"13"
],
"digest": {
"length": 470.0,
"function_hash": "164277845087912398136043904496309705968"
}
}
],
"fixes": [
"https://android.googlesource.com/platform/packages/services/Telephony/+/7f6575528f222e6b56b51ed07a02a53ca9b65ec9"
],
"types": [
"EoP"
],
"severity": "Moderate",
"spl": "2022-12-01"
}