{"id":"ASB-A-234442700", "published":"2023-03-01T00:00:00Z", "modified":"2026-05-01T15:24:27.653932157Z", "aliases":["CVE-2023-20929", "A-234442700"], "details":"In sendHalfSheetCancelBroadcast of HalfSheetActivity.java, there is a possible way to learn nearby BT MAC addresses due to an unrestricted broadcast intent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "affected":[{"package":{"name":"platform/packages/modules/Connectivity", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"13-next:0"}, {"fixed":"13-next:2023-03-01"}]}], "versions":["13-next"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/modules/Connectivity/+/fdc92430972a9bff3ff209473343a1f87105dfb2"], "severity":"High", "spl":"2023-03-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["328397260051996227135759261611843328454", "129359633994315351973004114942235482351", "42339847672469012809926555121913465245"], "threshold":0.9}, "id":"ASB-A-234442700-39ce7275", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/modules/Connectivity/+/fdc92430972a9bff3ff209473343a1f87105dfb2", "target":{"file":"nearby/halfsheet/src/com/android/nearby/halfsheet/utils/BroadcastUtils.java"}}, {"deprecated":false, "digest":{"line_hashes":["12788665894686877267506730894714524517", "195588258138639578094767316417063403974", "339716937456861031431965951494761331208", "182449640670693133972346222686709542026", "235406266822216302882684603830361310447"], "threshold":0.9}, "id":"ASB-A-234442700-6058ac53", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/modules/Connectivity/+/fdc92430972a9bff3ff209473343a1f87105dfb2", "target":{"file":"nearby/halfsheet/src/com/android/nearby/halfsheet/HalfSheetActivity.java"}}, {"deprecated":false, "digest":{"function_hash":"327631697207629074425264569555747175604", "length":809}, "id":"ASB-A-234442700-d63c7995", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/modules/Connectivity/+/fdc92430972a9bff3ff209473343a1f87105dfb2", "target":{"file":"nearby/halfsheet/src/com/android/nearby/halfsheet/HalfSheetActivity.java", "function":"sendHalfSheetCancelBroadcast"}}]}}, {"package":{"name":"platform/packages/modules/Connectivity", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"13:0"}, {"fixed":"13:2023-03-01"}]}], "versions":["13"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/modules/Connectivity/+/be99ea27e22ef97aec9a95ba6d5f52e954e9f2a7"], "severity":"High", "spl":"2023-03-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["328397260051996227135759261611843328454", "129359633994315351973004114942235482351", "42339847672469012809926555121913465245"], "threshold":0.9}, "id":"ASB-A-234442700-92378d8e", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/modules/Connectivity/+/be99ea27e22ef97aec9a95ba6d5f52e954e9f2a7", "target":{"file":"nearby/halfsheet/src/com/android/nearby/halfsheet/utils/BroadcastUtils.java"}}, {"deprecated":false, "digest":{"line_hashes":["213338859944832607795053376042387125202", "195588258138639578094767316417063403974", "339716937456861031431965951494761331208", "121188073611806899816116701627336654222", "263736280045250228447330093202858026001"], "threshold":0.9}, "id":"ASB-A-234442700-b9723b29", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/modules/Connectivity/+/be99ea27e22ef97aec9a95ba6d5f52e954e9f2a7", "target":{"file":"nearby/halfsheet/src/com/android/nearby/halfsheet/HalfSheetActivity.java"}}, {"deprecated":false, "digest":{"function_hash":"157480116973487508884925223063829323208", "length":800}, "id":"ASB-A-234442700-f68f42f5", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/modules/Connectivity/+/be99ea27e22ef97aec9a95ba6d5f52e954e9f2a7", "target":{"file":"nearby/halfsheet/src/com/android/nearby/halfsheet/HalfSheetActivity.java", "function":"sendHalfSheetCancelBroadcast"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2023-03-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/packages/modules/Connectivity/+/be99ea27e22ef97aec9a95ba6d5f52e954e9f2a7"}]}