Lucene search

K
osvGoogleOSV:ASB-A-185126149
HistoryAug 01, 2021 - 12:00 a.m.

Sensitive Iccid could be Sniffed by Intercepting ACTION_CONFIGURE_VOICEMAIL Implicit Intent in VoicemailSettingsFragment of Dialer

2021-08-0100:00:00
Google
osv.dev
8

5.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.9%

In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

5.2 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.9%

Related for OSV:ASB-A-185126149