In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 520.0, "function_hash": "124347352249865646556944936559596462054" }, "id": "ASB-A-155092443-5f46d6a7", "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7", "deprecated": false, "signature_version": "v1", "target": { "file": "src/java/com/android/internal/telephony/euicc/EuiccController.java", "function": "addResolutionIntent" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "117644871708654916346245945015463275626", "223665824716409487639496807541848082315", "153896511408108601377244622035927833590", "214338118115568385601977212861965221200", "252555523724162323221182265734240667994", "262626998732534039738096859923668305917", "284733846293931103168905718368524179728", "295496958192235468506319800338169638268", "73099640744412732828548186330436131037", "145124376558202810450310734881358587716", "227614234266439378251246365778538648135" ] }, "id": "ASB-A-155092443-b1a247c1", "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7", "deprecated": false, "signature_version": "v1", "target": { "file": "src/java/com/android/internal/telephony/euicc/EuiccController.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7" ], "spl": "2020-09-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "41947819677962889077519451532663704680", "102135948322594920735190946348112074288", "220160467030282996760638356047881540303", "253889126629877657108515330408653953158", "276112923747055330083233450457693907914" ] }, "id": "ASB-A-155092443-77c0601b", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/EmergencyCallbackModeService.java" }, "signature_type": "Line" }, { "digest": { "length": 1554.0, "function_hash": "239929725198670433305970540035158012328" }, "id": "ASB-A-155092443-910531fc", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/EmergencyCallbackModeService.java", "function": "showNotification" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2" ], "spl": "2020-09-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "117644871708654916346245945015463275626", "223665824716409487639496807541848082315", "153896511408108601377244622035927833590", "214338118115568385601977212861965221200", "252555523724162323221182265734240667994", "262626998732534039738096859923668305917", "284733846293931103168905718368524179728", "295496958192235468506319800338169638268", "73099640744412732828548186330436131037", "145124376558202810450310734881358587716", "227614234266439378251246365778538648135" ] }, "id": "ASB-A-155092443-319978f2", "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7", "deprecated": false, "signature_version": "v1", "target": { "file": "src/java/com/android/internal/telephony/euicc/EuiccController.java" }, "signature_type": "Line" }, { "digest": { "length": 520.0, "function_hash": "124347352249865646556944936559596462054" }, "id": "ASB-A-155092443-f24e9374", "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7", "deprecated": false, "signature_version": "v1", "target": { "file": "src/java/com/android/internal/telephony/euicc/EuiccController.java", "function": "addResolutionIntent" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7" ], "spl": "2020-09-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "41947819677962889077519451532663704680", "102135948322594920735190946348112074288", "220160467030282996760638356047881540303", "253889126629877657108515330408653953158", "276112923747055330083233450457693907914" ] }, "id": "ASB-A-155092443-7ceae2e0", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/EmergencyCallbackModeService.java" }, "signature_type": "Line" }, { "digest": { "length": 1554.0, "function_hash": "239929725198670433305970540035158012328" }, "id": "ASB-A-155092443-b9ee0d90", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/EmergencyCallbackModeService.java", "function": "showNotification" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2" ], "spl": "2020-09-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "117644871708654916346245945015463275626", "223665824716409487639496807541848082315", "153896511408108601377244622035927833590", "214338118115568385601977212861965221200", "252555523724162323221182265734240667994", "262626998732534039738096859923668305917", "284733846293931103168905718368524179728", "295496958192235468506319800338169638268", "73099640744412732828548186330436131037", "145124376558202810450310734881358587716", "227614234266439378251246365778538648135" ] }, "id": "ASB-A-155092443-9ad82ed8", "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7", "deprecated": false, "signature_version": "v1", "target": { "file": "src/java/com/android/internal/telephony/euicc/EuiccController.java" }, "signature_type": "Line" }, { "digest": { "length": 520.0, "function_hash": "124347352249865646556944936559596462054" }, "id": "ASB-A-155092443-a73ebb1c", "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7", "deprecated": false, "signature_version": "v1", "target": { "file": "src/java/com/android/internal/telephony/euicc/EuiccController.java", "function": "addResolutionIntent" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7" ], "spl": "2020-09-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "length": 1554.0, "function_hash": "239929725198670433305970540035158012328" }, "id": "ASB-A-155092443-1a42be31", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/EmergencyCallbackModeService.java", "function": "showNotification" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "41947819677962889077519451532663704680", "102135948322594920735190946348112074288", "220160467030282996760638356047881540303", "253889126629877657108515330408653953158", "276112923747055330083233450457693907914" ] }, "id": "ASB-A-155092443-573e3292", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/EmergencyCallbackModeService.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2" ], "spl": "2020-09-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "length": 520.0, "function_hash": "124347352249865646556944936559596462054" }, "id": "ASB-A-155092443-2aa7e155", "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7", "deprecated": false, "signature_version": "v1", "target": { "file": "src/java/com/android/internal/telephony/euicc/EuiccController.java", "function": "addResolutionIntent" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "117644871708654916346245945015463275626", "223665824716409487639496807541848082315", "153896511408108601377244622035927833590", "214338118115568385601977212861965221200", "252555523724162323221182265734240667994", "262626998732534039738096859923668305917", "284733846293931103168905718368524179728", "295496958192235468506319800338169638268", "73099640744412732828548186330436131037", "145124376558202810450310734881358587716", "227614234266439378251246365778538648135" ] }, "id": "ASB-A-155092443-3f845299", "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7", "deprecated": false, "signature_version": "v1", "target": { "file": "src/java/com/android/internal/telephony/euicc/EuiccController.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7" ], "spl": "2020-09-01", "severity": "High", "types": [ "ID" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "41947819677962889077519451532663704680", "102135948322594920735190946348112074288", "220160467030282996760638356047881540303", "253889126629877657108515330408653953158", "276112923747055330083233450457693907914" ] }, "id": "ASB-A-155092443-313eb20d", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/EmergencyCallbackModeService.java" }, "signature_type": "Line" }, { "digest": { "length": 1554.0, "function_hash": "239929725198670433305970540035158012328" }, "id": "ASB-A-155092443-aa484ca2", "source": "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/phone/EmergencyCallbackModeService.java", "function": "showNotification" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2" ], "spl": "2020-09-01", "severity": "High", "types": [ "ID" ] }