Platform Frameworks Opt Telephony vulnerabilities

16 known vulnerabilities affecting platform/frameworks_opt_telephony.

Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN16

Vulnerabilities

Page 1 of 1
CVE-2025-48618UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+3 more2025-12-01
CVE-2025-48618 CVE-2025-48618: In processLaunchBrowser of CommandParamsFactory In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to improper locking. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-48529UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48529 CVE-2025-48529: In setRingtoneUri of VoicemailNotificationSettingsUtil In setRingtoneUri of VoicemailNotificationSettingsUtil.java , there is a possible cross user data leak due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21184UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21184 CVE-2023-21184: In getCurrentPrivilegedPackagesForAllUsers of CarrierPrivilegesTracker In getCurrentPrivilegedPackagesForAllUsers of CarrierPrivilegesTracker.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20225UNKNOWN≥ 10:0, < 10:2022-07-01≥ 11:0, < 11:2022-07-01+2 more2022-07-01
CVE-2022-20225 CVE-2022-20225: In getSubscriptionProperty of SubscriptionController In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0643UNKNOWN≥ 10:0, < 10:2022-01-01≥ 11:0, < 11:2022-01-01+1 more2022-01-01
CVE-2021-0643 CVE-2021-0643: In getAllSubInfoList of SubscriptionController In getAllSubInfoList of SubscriptionController.java, there is a possible way to retrieve a long term identifier without the correct permissions due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1008UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1008 CVE-2021-1008: In addSubInfo of SubscriptionController In addSubInfo of SubscriptionController.java, there is a possible way to force the user to make a factory reset due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0990UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0990 CVE-2021-0990: In getDeviceId of PhoneSubInfoController In getDeviceId of PhoneSubInfoController.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0428UNKNOWN≥ 10:0, < 10:2021-09-012021-09-01
CVE-2021-0428 CVE-2021-0428: In getSimSerialNumber of TelephonyManager In getSimSerialNumber of TelephonyManager.java, there is a possible way to read a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0644UNKNOWN≥ 10:0, < 10:2021-09-01≥ 11:0, < 11:2021-09-012021-09-01
CVE-2021-0644 CVE-2021-0644: In conditionallyRemoveIdentifiers of SubscriptionController In conditionallyRemoveIdentifiers of SubscriptionController.java, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0641UNKNOWN≥ 8.1:0, < 8.1:2021-08-01≥ 9:0, < 9:2021-08-01+2 more2021-08-01
CVE-2021-0641 CVE-2021-0641: In getAvailableSubscriptionInfoList of SubscriptionController In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0538UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0538 CVE-2021-0538: In onCreate of EmergencyCallbackModeExitDialog In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0246UNKNOWN≥ 10:0, < 10:2020-10-01≥ 11:0, < 11:2020-10-012020-10-01
CVE-2020-0246 CVE-2020-0246: In getCarrierPrivilegeStatus of UiccAccessRule In getCarrierPrivilegeStatus of UiccAccessRule.java, there is a missing permission check. This could lead to local information disclosure of EID data with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0396UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0396 CVE-2020-0396: In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0395UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0395 CVE-2020-0395: In showNotification of EmergencyCallbackModeService In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0397UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0397 CVE-2020-0397: In getNotificationBuilder of CarrierServiceStateTracker In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0399UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0399 CVE-2020-0399: In showLimitedSimFunctionWarningNotification of NotificationMgr In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv