Platform Packages Services Telephony vulnerabilities
22 known vulnerabilities affecting platform/packages_services_telephony.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN22
Vulnerabilities
Page 1 of 2
CVE-2025-48586UNKNOWN≥ 16-qpr2-next:0, < 16-qpr2-next:2025-12-01≥ 15:0, < 15:2025-12-01+1 more2025-12-01
CVE-2025-48586 CVE-2025-48586: In onActivityResult of EditFdnContactScreen
In onActivityResult of EditFdnContactScreen.java, there is a possible way to leak contacts from the work profile due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-32346UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 16:0, < 16:2025-09-012025-09-01
CVE-2025-32346 CVE-2025-32346: In onActivityResult of VoicemailSettingsActivity
In onActivityResult of VoicemailSettingsActivity.java, there is a possible work profile contact number leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-22419UNKNOWN≥ 15-next:0, < 15-next:2025-04-01≥ 15:0, < 15:2025-04-01+2 more2025-04-01
CVE-2025-22419 CVE-2025-22419: In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlay attack
In multiple locations, there is a possible way to mislead the user into enabling malicious phone calls forwarding due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2024-49740UNKNOWN≥ 15-next:0, < 15-next:2025-03-01≥ 12:0, < 12:2025-03-01+4 more2025-03-01
CVE-2024-49740 CVE-2024-49740: In multiple locations, there is a possible crash loop due to resource exhaustion
In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35680UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 11:0, < 11:2023-09-01+3 more2023-09-01
CVE-2023-35680 CVE-2023-35680: In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy
In multiple locations, there is a possible way to import contacts belonging to other users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-35665UNKNOWN≥ 13-next:0, < 13-next:2023-09-01≥ 11:0, < 11:2023-09-01+3 more2023-09-01
CVE-2023-35665 CVE-2023-35665: In multiple files, there is a possible way to import a contact from another user due to a missing permission check
In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20913UNKNOWN≥ 10:0, < 10:2023-01-01≥ 11:0, < 11:2023-01-01+3 more2023-01-01
CVE-2023-20913 CVE-2023-20913: In onCreate of PhoneAccountSettingsActivity
In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to mislead the user into enabling a malicious phone account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20525UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20525 CVE-2022-20525: In enforceVisualVoicemailPackage of PhoneInterfaceManager
In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-39709UNKNOWN≥ 12:0, < 12:2022-03-01≥ 12L:0, < 12L:2022-03-012022-03-01
CVE-2021-39709 CVE-2021-39709: In sendSipAccountsRemovedNotification of SipAccountRegistry
In sendSipAccountsRemovedNotification of SipAccountRegistry.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1014UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1014 CVE-2021-1014: In getNetworkTypeForSubscriber of PhoneInterfaceManager
In getNetworkTypeForSubscriber of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1015UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1015 CVE-2021-1015: In getMeidForSlot of PhoneInterfaceManager
In getMeidForSlot of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0987UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-0987 CVE-2021-0987: In getNeighboringCellInfo of PhoneInterfaceManager
In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1005UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1005 CVE-2021-1005: In getDeviceIdWithFeature of PhoneInterfaceManager
In getDeviceIdWithFeature of PhoneInterfaceManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-0642UNKNOWN≥ 8.1:0, < 8.1:2021-08-01≥ 9:0, < 9:2021-08-01+2 more2021-08-01
CVE-2021-0642 CVE-2021-0642: In onResume of VoicemailSettingsFragment
In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permissions due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2021-0538UNKNOWN≥ 11:0, < 11:2021-06-012021-06-01
CVE-2021-0538 CVE-2021-0538: In onCreate of EmergencyCallbackModeExitDialog
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible exit of emergency callback mode due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2020-0400UNKNOWN≥ 10:0, < 10:2020-10-012020-10-01
CVE-2020-0400 CVE-2020-0400: In showDataRoamingNotification of NotificationMgr
In showDataRoamingNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0398UNKNOWN≥ 10:0, < 10:2020-10-012020-10-01
CVE-2020-0398 CVE-2020-0398: In updateMwi of NotificationMgr
In updateMwi of NotificationMgr.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0395UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0395 CVE-2020-0395: In showNotification of EmergencyCallbackModeService
In showNotification of EmergencyCallbackModeService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0397UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0397 CVE-2020-0397: In getNotificationBuilder of CarrierServiceStateTracker
In getNotificationBuilder of CarrierServiceStateTracker.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2020-0399UNKNOWN≥ 8.0:0, < 8.0:2020-09-01≥ 8.1:0, < 8.1:2020-09-01+2 more2020-09-01
CVE-2020-0399 CVE-2020-0399: In showLimitedSimFunctionWarningNotification of NotificationMgr
In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
osv
1 / 2Next →