{"id":"ASB-A-155092443","details":"In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-155092443","CVE-2020-0397"],"modified":"2026-05-25T16:46:24.913870386Z","published":"2020-09-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2020-09-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2"}],"affected":[{"package":{"name":"platform/frameworks/opt/telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0:0"},{"fixed":"8.0:2020-09-01"}]}],"versions":["8.0"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-155092443-5f46d6a7","deprecated":false,"digest":{"length":520,"function_hash":"124347352249865646556944936559596462054"},"source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7","target":{"function":"addResolutionIntent","file":"src/java/com/android/internal/telephony/euicc/EuiccController.java"},"signature_version":"v1","signature_type":"Function"},{"id":"ASB-A-155092443-b1a247c1","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7","target":{"file":"src/java/com/android/internal/telephony/euicc/EuiccController.java"},"digest":{"line_hashes":["117644871708654916346245945015463275626","223665824716409487639496807541848082315","153896511408108601377244622035927833590","214338118115568385601977212861965221200","252555523724162323221182265734240667994","262626998732534039738096859923668305917","284733846293931103168905718368524179728","295496958192235468506319800338169638268","73099640744412732828548186330436131037","145124376558202810450310734881358587716","227614234266439378251246365778538648135"],"threshold":0.9},"signature_type":"Line"}],"types":["ID"],"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7"],"spl":"2020-09-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-155092443.json"}},{"package":{"name":"platform/packages/services/Telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0:0"},{"fixed":"8.0:2020-09-01"}]}],"versions":["8.0"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-155092443-77c0601b","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2","target":{"file":"src/com/android/phone/EmergencyCallbackModeService.java"},"digest":{"line_hashes":["41947819677962889077519451532663704680","102135948322594920735190946348112074288","220160467030282996760638356047881540303","253889126629877657108515330408653953158","276112923747055330083233450457693907914"],"threshold":0.9},"signature_type":"Line"},{"id":"ASB-A-155092443-910531fc","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2","target":{"function":"showNotification","file":"src/com/android/phone/EmergencyCallbackModeService.java"},"digest":{"length":1554,"function_hash":"239929725198670433305970540035158012328"},"signature_type":"Function"}],"types":["ID"],"severity":"High","spl":"2020-09-01","fixes":["https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-155092443.json"}},{"package":{"name":"platform/frameworks/opt/telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.1:0"},{"fixed":"8.1:2020-09-01"}]}],"versions":["8.1"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-155092443-319978f2","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7","target":{"file":"src/java/com/android/internal/telephony/euicc/EuiccController.java"},"digest":{"line_hashes":["117644871708654916346245945015463275626","223665824716409487639496807541848082315","153896511408108601377244622035927833590","214338118115568385601977212861965221200","252555523724162323221182265734240667994","262626998732534039738096859923668305917","284733846293931103168905718368524179728","295496958192235468506319800338169638268","73099640744412732828548186330436131037","145124376558202810450310734881358587716","227614234266439378251246365778538648135"],"threshold":0.9},"signature_type":"Line"},{"id":"ASB-A-155092443-f24e9374","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7","target":{"function":"addResolutionIntent","file":"src/java/com/android/internal/telephony/euicc/EuiccController.java"},"digest":{"length":520,"function_hash":"124347352249865646556944936559596462054"},"signature_type":"Function"}],"types":["ID"],"severity":"High","spl":"2020-09-01","fixes":["https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-155092443.json"}},{"package":{"name":"platform/packages/services/Telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.1:0"},{"fixed":"8.1:2020-09-01"}]}],"versions":["8.1"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-155092443-7ceae2e0","deprecated":false,"digest":{"line_hashes":["41947819677962889077519451532663704680","102135948322594920735190946348112074288","220160467030282996760638356047881540303","253889126629877657108515330408653953158","276112923747055330083233450457693907914"],"threshold":0.9},"source":"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2","target":{"file":"src/com/android/phone/EmergencyCallbackModeService.java"},"signature_version":"v1","signature_type":"Line"},{"id":"ASB-A-155092443-b9ee0d90","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2","target":{"function":"showNotification","file":"src/com/android/phone/EmergencyCallbackModeService.java"},"digest":{"length":1554,"function_hash":"239929725198670433305970540035158012328"},"signature_type":"Function"}],"types":["ID"],"severity":"High","spl":"2020-09-01","fixes":["https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-155092443.json"}},{"package":{"name":"platform/frameworks/opt/telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9:0"},{"fixed":"9:2020-09-01"}]}],"versions":["9"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-155092443-9ad82ed8","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7","target":{"file":"src/java/com/android/internal/telephony/euicc/EuiccController.java"},"digest":{"line_hashes":["117644871708654916346245945015463275626","223665824716409487639496807541848082315","153896511408108601377244622035927833590","214338118115568385601977212861965221200","252555523724162323221182265734240667994","262626998732534039738096859923668305917","284733846293931103168905718368524179728","295496958192235468506319800338169638268","73099640744412732828548186330436131037","145124376558202810450310734881358587716","227614234266439378251246365778538648135"],"threshold":0.9},"signature_type":"Line"},{"id":"ASB-A-155092443-a73ebb1c","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7","target":{"function":"addResolutionIntent","file":"src/java/com/android/internal/telephony/euicc/EuiccController.java"},"digest":{"length":520,"function_hash":"124347352249865646556944936559596462054"},"signature_type":"Function"}],"types":["ID"],"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7"],"spl":"2020-09-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-155092443.json"}},{"package":{"name":"platform/packages/services/Telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9:0"},{"fixed":"9:2020-09-01"}]}],"versions":["9"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-155092443-1a42be31","deprecated":false,"digest":{"length":1554,"function_hash":"239929725198670433305970540035158012328"},"source":"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2","target":{"function":"showNotification","file":"src/com/android/phone/EmergencyCallbackModeService.java"},"signature_version":"v1","signature_type":"Function"},{"id":"ASB-A-155092443-573e3292","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2","target":{"file":"src/com/android/phone/EmergencyCallbackModeService.java"},"digest":{"line_hashes":["41947819677962889077519451532663704680","102135948322594920735190946348112074288","220160467030282996760638356047881540303","253889126629877657108515330408653953158","276112923747055330083233450457693907914"],"threshold":0.9},"signature_type":"Line"}],"types":["ID"],"severity":"High","spl":"2020-09-01","fixes":["https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-155092443.json"}},{"package":{"name":"platform/frameworks/opt/telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2020-09-01"}]}],"versions":["10"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-155092443-2aa7e155","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7","target":{"function":"addResolutionIntent","file":"src/java/com/android/internal/telephony/euicc/EuiccController.java"},"digest":{"length":520,"function_hash":"124347352249865646556944936559596462054"},"signature_type":"Function"},{"id":"ASB-A-155092443-3f845299","deprecated":false,"digest":{"line_hashes":["117644871708654916346245945015463275626","223665824716409487639496807541848082315","153896511408108601377244622035927833590","214338118115568385601977212861965221200","252555523724162323221182265734240667994","262626998732534039738096859923668305917","284733846293931103168905718368524179728","295496958192235468506319800338169638268","73099640744412732828548186330436131037","145124376558202810450310734881358587716","227614234266439378251246365778538648135"],"threshold":0.9},"source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7","target":{"file":"src/java/com/android/internal/telephony/euicc/EuiccController.java"},"signature_version":"v1","signature_type":"Line"}],"types":["ID"],"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/opt/telephony/+/0126084de146b51a842d7604cddb3303f46cade7"],"spl":"2020-09-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-155092443.json"}},{"package":{"name":"platform/packages/services/Telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2020-09-01"}]}],"versions":["10"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-155092443-313eb20d","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2","target":{"file":"src/com/android/phone/EmergencyCallbackModeService.java"},"digest":{"line_hashes":["41947819677962889077519451532663704680","102135948322594920735190946348112074288","220160467030282996760638356047881540303","253889126629877657108515330408653953158","276112923747055330083233450457693907914"],"threshold":0.9},"signature_type":"Line"},{"id":"ASB-A-155092443-aa484ca2","deprecated":false,"digest":{"length":1554,"function_hash":"239929725198670433305970540035158012328"},"source":"https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2","target":{"function":"showNotification","file":"src/com/android/phone/EmergencyCallbackModeService.java"},"signature_version":"v1","signature_type":"Function"}],"types":["ID"],"severity":"High","spl":"2020-09-01","fixes":["https://android.googlesource.com/platform/packages/services/Telephony/+/11c41d321d0c2dc3631f37d2f8f3ebc745f454d2"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-155092443.json"}}],"schema_version":"1.7.5"}