The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x prior to 5.1.1 LMY49H and 6.x prior to 2016-03-01 does not check for the READ_PHONE_STATE permission, which allows malicious users to obtain sensitive information via a crafted application, aka internal bug 25778215.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
google android 5.0.2 |
||
google android 5.0.1 |
||
google android 6.0.1 |
||
google android 6.0 |
||
google android 5.1.1 |
||
google android 5.1.0 |
||
google android 5.1 |
||
google android 5.0 |