In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 967.0, "function_hash": "95813100806952752517657637119407566504" }, "id": "ASB-A-329058967-18c5afe1", "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/8c619f58c00047ab0ec687cd231bf93a08db6d55", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/server/telecom/ConnectionServiceWrapper.java", "function": "handleCreateConferenceComplete" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "100326431459558569292119600264389787165", "224460809244113809053494007357703622319", "333762841701727134505390074716578964885", "199218706011219857461499847670488384710", "19256926819814878956514261880855948330", "139717360613838074749875733557269753678", "183664305217219171351514465603028527937", "139804455583322841000522678523842891823" ] }, "id": "ASB-A-329058967-38e4146e", "source": "https://android.googlesource.com/platform/packages/services/Telecomm/+/8c619f58c00047ab0ec687cd231bf93a08db6d55", "deprecated": false, "signature_version": "v1", "target": { "file": "src/com/android/server/telecom/ConnectionServiceWrapper.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/packages/services/Telecomm/+/8c619f58c00047ab0ec687cd231bf93a08db6d55" ], "spl": "2024-09-01", "severity": "High", "types": [ "ID" ] }