{"id":"ASB-A-223578534","details":"In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call without permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-223578534","CVE-2022-20223"],"modified":"2026-05-25T16:46:24.913870386Z","published":"2022-07-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2022-07-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/apps/Settings/+/abadb382114fa8af5209295c9bae2ca2b08935f3"}],"affected":[{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10:0"},{"fixed":"10:2022-07-01"}]}],"versions":["10"],"ecosystem_specific":{"vanir_signatures":[{"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/b3eecdd13d9f3d9fde99e9881c9e451ff199f7ad","deprecated":false,"signature_version":"v1","target":{"function":"assertSafeToStartCustomActivity","file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"id":"ASB-A-223578534-bd2fef27","digest":{"function_hash":"230728443153871352391391556050698896647","length":489}},{"signature_type":"Line","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/b3eecdd13d9f3d9fde99e9881c9e451ff199f7ad","deprecated":false,"signature_version":"v1","target":{"file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"id":"ASB-A-223578534-f098c976","digest":{"line_hashes":["232477022807444841013375170475551310078","146625305168494414691894218653073493704","109457721975710769064585912225534305770","42352054353086035454349671191144762807","284514082129184479650462996686183383481","33376965427845241378269936173562622954"],"threshold":0.9}}],"spl":"2022-07-01","severity":"High","types":["EoP"],"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/b3eecdd13d9f3d9fde99e9881c9e451ff199f7ad"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-223578534.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11:0"},{"fixed":"11:2022-07-01"}]}],"versions":["11"],"ecosystem_specific":{"severity":"High","vanir_signatures":[{"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/aeb36e5c282ac9cdfb34e87f68b8d8a5067d644d","deprecated":false,"signature_version":"v1","target":{"function":"assertSafeToStartCustomActivity","file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"id":"ASB-A-223578534-70caad6e","digest":{"function_hash":"230728443153871352391391556050698896647","length":489}},{"signature_type":"Line","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/aeb36e5c282ac9cdfb34e87f68b8d8a5067d644d","deprecated":false,"signature_version":"v1","target":{"file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"id":"ASB-A-223578534-afaf5a70","digest":{"line_hashes":["232477022807444841013375170475551310078","146625305168494414691894218653073493704","109457721975710769064585912225534305770","42352054353086035454349671191144762807","284514082129184479650462996686183383481","33376965427845241378269936173562622954"],"threshold":0.9}}],"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/aeb36e5c282ac9cdfb34e87f68b8d8a5067d644d"],"types":["EoP"],"spl":"2022-07-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-223578534.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2022-07-01"}]}],"versions":["12"],"ecosystem_specific":{"severity":"High","vanir_signatures":[{"signature_type":"Line","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/f8f45888e6d20b238b222b95d18898fa1ab81ed4","target":{"file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","deprecated":false,"id":"ASB-A-223578534-0b473dfc","digest":{"line_hashes":["232477022807444841013375170475551310078","146625305168494414691894218653073493704","109457721975710769064585912225534305770","42352054353086035454349671191144762807","284514082129184479650462996686183383481","33376965427845241378269936173562622954"],"threshold":0.9}},{"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/f8f45888e6d20b238b222b95d18898fa1ab81ed4","deprecated":false,"signature_version":"v1","target":{"function":"assertSafeToStartCustomActivity","file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"id":"ASB-A-223578534-5f63e23f","digest":{"function_hash":"230728443153871352391391556050698896647","length":489}}],"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/f8f45888e6d20b238b222b95d18898fa1ab81ed4"],"types":["EoP"],"spl":"2022-07-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-223578534.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12L:0"},{"fixed":"12L:2022-07-01"}]}],"versions":["12L"],"ecosystem_specific":{"vanir_signatures":[{"signature_type":"Function","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/019eb77224b0671458ad447f15a2a29935c866c6","deprecated":false,"signature_version":"v1","target":{"function":"assertSafeToStartCustomActivity","file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"id":"ASB-A-223578534-6ba22492","digest":{"function_hash":"230728443153871352391391556050698896647","length":489}},{"signature_type":"Line","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/019eb77224b0671458ad447f15a2a29935c866c6","deprecated":false,"signature_version":"v1","target":{"file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"id":"ASB-A-223578534-cc55d9bd","digest":{"line_hashes":["232477022807444841013375170475551310078","146625305168494414691894218653073493704","109457721975710769064585912225534305770","42352054353086035454349671191144762807","284514082129184479650462996686183383481","33376965427845241378269936173562622954"],"threshold":0.9}}],"spl":"2022-07-01","fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/019eb77224b0671458ad447f15a2a29935c866c6"],"types":["EoP"],"severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-223578534.json"}}],"schema_version":"1.7.5"}