In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "106680201593422794262120843882354478791", "326774004061573496066568127664103587028", "295395256957196504913463328355904672893", "149183730702223882063009548301812832852", "111530533399569871322797409736703837069", "164450686893749293223111827008859727071", "72195964722680638204432878196194950937", "172334718998239283189666931642852725078" ] }, "id": "ASB-A-185126549-2f5d2b96", "source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b", "deprecated": false, "signature_version": "v1", "target": { "file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java" }, "signature_type": "Line" }, { "digest": { "length": 1385.0, "function_hash": "242911685893440700542492214997579498592" }, "id": "ASB-A-185126549-c19e1d43", "source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b", "deprecated": false, "signature_version": "v1", "target": { "file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java", "function": "sendLegacyVoicemailNotification" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b" ], "spl": "2022-01-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "106680201593422794262120843882354478791", "326774004061573496066568127664103587028", "295395256957196504913463328355904672893", "149183730702223882063009548301812832852", "111530533399569871322797409736703837069", "164450686893749293223111827008859727071", "72195964722680638204432878196194950937", "172334718998239283189666931642852725078" ] }, "id": "ASB-A-185126549-47c021ac", "source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b", "deprecated": false, "signature_version": "v1", "target": { "file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java" }, "signature_type": "Line" }, { "digest": { "length": 1385.0, "function_hash": "242911685893440700542492214997579498592" }, "id": "ASB-A-185126549-6c87a72c", "source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b", "deprecated": false, "signature_version": "v1", "target": { "file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java", "function": "sendLegacyVoicemailNotification" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b" ], "spl": "2022-01-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "106680201593422794262120843882354478791", "326774004061573496066568127664103587028", "295395256957196504913463328355904672893", "149183730702223882063009548301812832852", "111530533399569871322797409736703837069", "164450686893749293223111827008859727071", "72195964722680638204432878196194950937", "172334718998239283189666931642852725078" ] }, "id": "ASB-A-185126549-c7359f3d", "source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b", "deprecated": false, "signature_version": "v1", "target": { "file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java" }, "signature_type": "Line" }, { "digest": { "length": 1385.0, "function_hash": "242911685893440700542492214997579498592" }, "id": "ASB-A-185126549-f4f18912", "source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b", "deprecated": false, "signature_version": "v1", "target": { "file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java", "function": "sendLegacyVoicemailNotification" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b" ], "spl": "2022-01-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "106680201593422794262120843882354478791", "326774004061573496066568127664103587028", "295395256957196504913463328355904672893", "149183730702223882063009548301812832852", "111530533399569871322797409736703837069", "164450686893749293223111827008859727071", "72195964722680638204432878196194950937", "172334718998239283189666931642852725078" ] }, "id": "ASB-A-185126549-7d5c7dd5", "source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b", "deprecated": false, "signature_version": "v1", "target": { "file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java" }, "signature_type": "Line" }, { "digest": { "length": 1385.0, "function_hash": "242911685893440700542492214997579498592" }, "id": "ASB-A-185126549-fc45b3ca", "source": "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b", "deprecated": false, "signature_version": "v1", "target": { "file": "java/com/android/voicemail/impl/sms/LegacyModeSmsHandler.java", "function": "sendLegacyVoicemailNotification" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Dialer/+/bdd6d1ea00f94296c251f4340a52a2035167370b" ], "spl": "2022-01-01", "severity": "High", "types": [ "EoP" ] }