ASB-A-208817618 PUBLISHED

In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

Affected Products

VendorProductVersions
platformpackages/services/Telephony12:0, 12, 12L:0

Timeline

References

Open in Interactive Console →