{"id":"ASB-A-213457638","details":"In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-213457638","CVE-2022-20225"],"modified":"2026-05-25T16:46:24.913870386Z","published":"2022-07-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2022-07-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/37d1a266646b4fedda3bcab73eb1c1f01285c4be"}],"affected":[{"package":{"name":"platform/frameworks/opt/telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2022-07-01"}]}],"versions":["10"],"ecosystem_specific":{"vanir_signatures":[{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/12db8db9b127a3a9b414a8a09f6445c2a58f553e","target":{"file":"src/java/com/android/internal/telephony/SubscriptionController.java"},"id":"ASB-A-213457638-9602207d","signature_type":"Line","digest":{"line_hashes":["170798595294613678534493715480809551648","85731751937280490573074621419231066066","252207569181961741661285617994400762952","323547277187699899198361067369519416581","198922279478817670410977329260599765369","248199077134062676251498125742683059126"],"threshold":0.9}},{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/12db8db9b127a3a9b414a8a09f6445c2a58f553e","target":{"file":"src/java/com/android/internal/telephony/SubscriptionController.java","function":"getSubscriptionProperty"},"id":"ASB-A-213457638-a6d27dfd","signature_type":"Function","digest":{"function_hash":"93347553898625176689672612339351455415","length":304}}],"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/opt/telephony/+/12db8db9b127a3a9b414a8a09f6445c2a58f553e"],"spl":"2022-07-01","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-213457638.json"}},{"package":{"name":"platform/frameworks/opt/telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2022-07-01"}]}],"versions":["11"],"ecosystem_specific":{"vanir_signatures":[{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/7f3dd2afda9546b8a08897b016393cd5fd54c8b6","target":{"file":"src/java/com/android/internal/telephony/SubscriptionController.java"},"id":"ASB-A-213457638-4dbd36a4","signature_type":"Line","digest":{"line_hashes":["318345005099167175638735175515408360866","76227838461729289359626885894136257225","208298297523743708379249323017622388267","141661230186442120772611226493047929364","72390182219535305868655594069327153162","248199077134062676251498125742683059126"],"threshold":0.9}},{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/7f3dd2afda9546b8a08897b016393cd5fd54c8b6","target":{"file":"src/java/com/android/internal/telephony/SubscriptionController.java","function":"getSubscriptionProperty"},"id":"ASB-A-213457638-db612bca","signature_type":"Function","digest":{"function_hash":"69897029542924365489245474301636154119","length":326}}],"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/opt/telephony/+/7f3dd2afda9546b8a08897b016393cd5fd54c8b6"],"spl":"2022-07-01","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-213457638.json"}},{"package":{"name":"platform/frameworks/opt/telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2022-07-01"}]}],"versions":["12"],"ecosystem_specific":{"vanir_signatures":[{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/e873e764b9c3af081bc3155eab54fa6027f7785c","target":{"file":"src/java/com/android/internal/telephony/SubscriptionController.java"},"id":"ASB-A-213457638-bcaba9df","signature_type":"Line","digest":{"line_hashes":["318345005099167175638735175515408360866","76227838461729289359626885894136257225","208298297523743708379249323017622388267","141661230186442120772611226493047929364","72390182219535305868655594069327153162","248199077134062676251498125742683059126"],"threshold":0.9}},{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/e873e764b9c3af081bc3155eab54fa6027f7785c","target":{"file":"src/java/com/android/internal/telephony/SubscriptionController.java","function":"getSubscriptionProperty"},"id":"ASB-A-213457638-fa22aeb8","signature_type":"Function","digest":{"function_hash":"69897029542924365489245474301636154119","length":326}}],"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/opt/telephony/+/e873e764b9c3af081bc3155eab54fa6027f7785c"],"types":["ID"],"spl":"2022-07-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-213457638.json"}},{"package":{"name":"platform/frameworks/opt/telephony","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12L:0"},{"fixed":"12L:2022-07-01"}]}],"versions":["12L"],"ecosystem_specific":{"vanir_signatures":[{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/b7399246a90b2125ccca606e7eb3c5e7e2160cdb","target":{"file":"src/java/com/android/internal/telephony/SubscriptionController.java","function":"getSubscriptionProperty"},"id":"ASB-A-213457638-0522e7df","signature_type":"Function","digest":{"function_hash":"69897029542924365489245474301636154119","length":326}},{"signature_version":"v1","deprecated":false,"source":"https://android.googlesource.com/platform/frameworks/opt/telephony/+/b7399246a90b2125ccca606e7eb3c5e7e2160cdb","target":{"file":"src/java/com/android/internal/telephony/SubscriptionController.java"},"id":"ASB-A-213457638-6fa8f9cc","signature_type":"Line","digest":{"line_hashes":["318345005099167175638735175515408360866","76227838461729289359626885894136257225","208298297523743708379249323017622388267","141661230186442120772611226493047929364","72390182219535305868655594069327153162","248199077134062676251498125742683059126"],"threshold":0.9}}],"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/opt/telephony/+/b7399246a90b2125ccca606e7eb3c5e7e2160cdb"],"types":["ID"],"spl":"2022-07-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-213457638.json"}}],"schema_version":"1.7.5"}