HomeDefault status
unaffected
17
affected
Description
In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Elevation of privilege
Product status
17
References
source.android.com/docs/security/bulletin/android-17