{"id":"ASB-A-288896269", "published":"2023-12-01T00:00:00Z", "modified":"2026-04-29T15:10:00.007170452Z", "aliases":["CVE-2023-40098", "A-288896269"], "details":"In mOnDone of NotificationConversationInfo.java, there is a possible way to access app notification data of another user due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "affected":[{"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"14-next:0"}, {"fixed":"14-next:2023-12-01"}]}], "versions":["14-next"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/adf620316dcfaf19d7d4a73e2c63322b4a3a4d3a"], "severity":"High", "spl":"2023-12-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"275790296995513726427829673377107683482", "length":1576}, "id":"ASB-A-288896269-4d8a678d", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/adf620316dcfaf19d7d4a73e2c63322b4a3a4d3a", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationConversationInfo.java", "function":"bindNotification"}}, {"deprecated":false, "digest":{"line_hashes":["265953387334128417533783229142107824643", "128925952502831700169030010272114177992", "138896328595853320761776874839011791774", "160616190006747144472108337585292575911", "228015238009796341240327091250876932018", "71600874674562408720298518993654728673", "59657049733372196380068050961988523682", "194903749351548277678970832090882712657", "111501335088025618588057779761888179250", "305795497846898578712863349790280066572", "198614634917747897042426569678831764695", "33809323543126496807564377033955698641", "3061521919880570451099164147101699862", "268289310753455125116496969042687087741", "128489441790955251978555926619893030340", "332085048172746370719374279780517669107", "304241201541386732293525466416520158958", "280933088920217115505016103242846997263", "161585619226953498893885346298666061327"], "threshold":0.9}, "id":"ASB-A-288896269-5700c026", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/adf620316dcfaf19d7d4a73e2c63322b4a3a4d3a", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationConversationInfo.java"}}, {"deprecated":false, "digest":{"function_hash":"97586018491712111788720419061632568428", "length":1007}, "id":"ASB-A-288896269-5908d504", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/adf620316dcfaf19d7d4a73e2c63322b4a3a4d3a", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java", "function":"NotificationGutsManager"}}, {"deprecated":false, "digest":{"function_hash":"277091814411092081832620044540052517237", "length":1596}, "id":"ASB-A-288896269-7da48cb8", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/adf620316dcfaf19d7d4a73e2c63322b4a3a4d3a", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java", "function":"initializeConversationNotificationInfo"}}, {"deprecated":false, "digest":{"line_hashes":["250030163650702690218556814786070496467", "131310132713107569074546476544284301339", "200454172663836146017633787901049385944", "256631679654335705417997342968732696046", "60800081678460235282324025511543154992", "184029382496790418619655563721822200537", "144532002353641202108734101213349969251", "312432234744021497199616349711957352583", "299835800258771234386313081000909342564", "11251168981888847700427063204746697821", "3478132542860705786686384393193862126", "57957579615136433794160362532557502014", "216051915126484363564419485253569070130", "112219203957012154437837566026893687200", "167870209374219206177625039945305653474", "235885022108293952125383790887580950514", "94051001812651911373192909752203608523", "338111167483887221304864265345565092383", "93231106277635975303741366827246226731", "16238322785248966224942093181591361924"], "threshold":0.9}, "id":"ASB-A-288896269-a8664fb2", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/adf620316dcfaf19d7d4a73e2c63322b4a3a4d3a", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"12:0"}, {"fixed":"12:2023-12-01"}]}], "versions":["12"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/b0522df0a33d0165656797df7edab978cb403bd4"], "severity":"High", "spl":"2023-12-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"148880730089168082794866880690815489815", "length":881}, "id":"ASB-A-288896269-52104215", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/b0522df0a33d0165656797df7edab978cb403bd4", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java", "function":"NotificationGutsManager"}}, {"deprecated":false, "digest":{"line_hashes":["265953387334128417533783229142107824643", "128925952502831700169030010272114177992", "138896328595853320761776874839011791774", "160616190006747144472108337585292575911", "228015238009796341240327091250876932018", "71600874674562408720298518993654728673", "59657049733372196380068050961988523682", "52195069929396233675454552345243074885", "251745224700952836749914186730387791260", "75882111226076295942487405329139410530", "64136458640941196898083386928760440656", "112513055506394179176074909462258007691", "198614634917747897042426569678831764695", "303560093868668070691232218874229168982", "203181757443446892219905689705187323361", "268289310753455125116496969042687087741", "128489441790955251978555926619893030340", "332085048172746370719374279780517669107", "304241201541386732293525466416520158958", "280933088920217115505016103242846997263", "161585619226953498893885346298666061327"], "threshold":0.9}, "id":"ASB-A-288896269-62c72999", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/b0522df0a33d0165656797df7edab978cb403bd4", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationConversationInfo.java"}}, {"deprecated":false, "digest":{"line_hashes":["202423729764277837459330863389223826032", "149637711870791475439214501699369946947", "45164103961923015352548044016399637543", "90616013806748030587310345061725384465", "83036082872288204524710312751447281102", "263288044336644581958528683740516952300", "100776016335977268769395061763150185638", "139279611553483094861445348210041438293", "278708482124900979312389608318767881776", "203378636160739123584612189496557695371", "252392960709280821845012763715727804687", "281264446443945558807586086307403930158"], "threshold":0.9}, "id":"ASB-A-288896269-937ac271", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/b0522df0a33d0165656797df7edab978cb403bd4", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/dagger/NotificationsModule.java"}}, {"deprecated":false, "digest":{"function_hash":"316910474760991676319562680710809790311", "length":1649}, "id":"ASB-A-288896269-c36af31b", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/b0522df0a33d0165656797df7edab978cb403bd4", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationConversationInfo.java", "function":"bindNotification"}}, {"deprecated":false, "digest":{"line_hashes":["250030163650702690218556814786070496467", "131310132713107569074546476544284301339", "200454172663836146017633787901049385944", "256631679654335705417997342968732696046", "312791754320742168449884174106375237751", "277227618549493534062934707979794410558", "220988877961902772679017382083177329450", "312432234744021497199616349711957352583", "83036082872288204524710312751447281102", "263288044336644581958528683740516952300", "100776016335977268769395061763150185638", "139279611553483094861445348210041438293", "186144590417932858439520096794134518573", "221536014066874596426273631637584292499", "166857196917069435929397588459026084634", "188163968223791024560792090100164186770", "189259908505359799866966181673239147712", "211645088009758618415743361212521862817", "93231106277635975303741366827246226731", "16238322785248966224942093181591361924"], "threshold":0.9}, "id":"ASB-A-288896269-d29b11c9", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/b0522df0a33d0165656797df7edab978cb403bd4", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java"}}, {"deprecated":false, "digest":{"function_hash":"144932520929737556307665606509048968832", "length":1613}, "id":"ASB-A-288896269-e5f1f5b1", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/b0522df0a33d0165656797df7edab978cb403bd4", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java", "function":"initializeConversationNotificationInfo"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"12L:0"}, {"fixed":"12L:2023-12-01"}]}], "versions":["12L"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/95659d74cfa1f6d7a9796b5d595c99df253ec054"], "severity":"High", "spl":"2023-12-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["250030163650702690218556814786070496467", "131310132713107569074546476544284301339", "200454172663836146017633787901049385944", "256631679654335705417997342968732696046", "60800081678460235282324025511543154992", "184029382496790418619655563721822200537", "144532002353641202108734101213349969251", "312432234744021497199616349711957352583", "83036082872288204524710312751447281102", "263288044336644581958528683740516952300", "100776016335977268769395061763150185638", "139279611553483094861445348210041438293", "216051915126484363564419485253569070130", "112219203957012154437837566026893687200", "167870209374219206177625039945305653474", "235885022108293952125383790887580950514", "189259908505359799866966181673239147712", "211645088009758618415743361212521862817", "93231106277635975303741366827246226731", "16238322785248966224942093181591361924"], "threshold":0.9}, "id":"ASB-A-288896269-0a414352", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/95659d74cfa1f6d7a9796b5d595c99df253ec054", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java"}}, {"deprecated":false, "digest":{"line_hashes":["265953387334128417533783229142107824643", "128925952502831700169030010272114177992", "138896328595853320761776874839011791774", "160616190006747144472108337585292575911", "228015238009796341240327091250876932018", "71600874674562408720298518993654728673", "59657049733372196380068050961988523682", "75882111226076295942487405329139410530", "64136458640941196898083386928760440656", "112513055506394179176074909462258007691", "198614634917747897042426569678831764695", "303560093868668070691232218874229168982", "203181757443446892219905689705187323361", "268289310753455125116496969042687087741", "128489441790955251978555926619893030340", "332085048172746370719374279780517669107", "304241201541386732293525466416520158958", "280933088920217115505016103242846997263", "161585619226953498893885346298666061327"], "threshold":0.9}, "id":"ASB-A-288896269-2e8e3a38", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/95659d74cfa1f6d7a9796b5d595c99df253ec054", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationConversationInfo.java"}}, {"deprecated":false, "digest":{"function_hash":"316910474760991676319562680710809790311", "length":1649}, "id":"ASB-A-288896269-31cb41cf", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/95659d74cfa1f6d7a9796b5d595c99df253ec054", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationConversationInfo.java", "function":"bindNotification"}}, {"deprecated":false, "digest":{"line_hashes":["202423729764277837459330863389223826032", "149637711870791475439214501699369946947", "45164103961923015352548044016399637543", "90616013806748030587310345061725384465", "83036082872288204524710312751447281102", "263288044336644581958528683740516952300", "100776016335977268769395061763150185638", "139279611553483094861445348210041438293", "278708482124900979312389608318767881776", "203378636160739123584612189496557695371", "252392960709280821845012763715727804687", "281264446443945558807586086307403930158"], "threshold":0.9}, "id":"ASB-A-288896269-8ca14599", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/95659d74cfa1f6d7a9796b5d595c99df253ec054", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/dagger/NotificationsModule.java"}}, {"deprecated":false, "digest":{"function_hash":"118208187244745841379262631806642852851", "length":895}, "id":"ASB-A-288896269-9bc6d9b6", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/95659d74cfa1f6d7a9796b5d595c99df253ec054", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java", "function":"NotificationGutsManager"}}, {"deprecated":false, "digest":{"function_hash":"144932520929737556307665606509048968832", "length":1613}, "id":"ASB-A-288896269-ce222ee3", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/95659d74cfa1f6d7a9796b5d595c99df253ec054", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java", "function":"initializeConversationNotificationInfo"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"13:0"}, {"fixed":"13:2023-12-01"}]}], "versions":["13"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/7444c007743970a9d6877c1b3fd2b28143687281"], "severity":"High", "spl":"2023-12-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"316910474760991676319562680710809790311", "length":1649}, "id":"ASB-A-288896269-02533e78", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/7444c007743970a9d6877c1b3fd2b28143687281", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationConversationInfo.java", "function":"bindNotification"}}, {"deprecated":false, "digest":{"line_hashes":["250030163650702690218556814786070496467", "131310132713107569074546476544284301339", "200454172663836146017633787901049385944", "256631679654335705417997342968732696046", "60800081678460235282324025511543154992", "184029382496790418619655563721822200537", "144532002353641202108734101213349969251", "312432234744021497199616349711957352583", "83036082872288204524710312751447281102", "263288044336644581958528683740516952300", "100776016335977268769395061763150185638", "139279611553483094861445348210041438293", "216051915126484363564419485253569070130", "112219203957012154437837566026893687200", "167870209374219206177625039945305653474", "235885022108293952125383790887580950514", "189259908505359799866966181673239147712", "211645088009758618415743361212521862817", "93231106277635975303741366827246226731", "16238322785248966224942093181591361924"], "threshold":0.9}, "id":"ASB-A-288896269-5917e25e", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/7444c007743970a9d6877c1b3fd2b28143687281", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java"}}, {"deprecated":false, "digest":{"line_hashes":["202423729764277837459330863389223826032", "149637711870791475439214501699369946947", "45164103961923015352548044016399637543", "90616013806748030587310345061725384465", "83036082872288204524710312751447281102", "263288044336644581958528683740516952300", "100776016335977268769395061763150185638", "139279611553483094861445348210041438293", "278708482124900979312389608318767881776", "203378636160739123584612189496557695371", "252392960709280821845012763715727804687", "281264446443945558807586086307403930158"], "threshold":0.9}, "id":"ASB-A-288896269-c1c73a42", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/7444c007743970a9d6877c1b3fd2b28143687281", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/dagger/NotificationsModule.java"}}, {"deprecated":false, "digest":{"function_hash":"308819479757998318616934749308127298072", "length":1619}, "id":"ASB-A-288896269-ce8d1cbf", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/7444c007743970a9d6877c1b3fd2b28143687281", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java", "function":"initializeConversationNotificationInfo"}}, {"deprecated":false, "digest":{"function_hash":"167081506323013977108977122307933165843", "length":901}, "id":"ASB-A-288896269-de38c169", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/7444c007743970a9d6877c1b3fd2b28143687281", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java", "function":"NotificationGutsManager"}}, {"deprecated":false, "digest":{"line_hashes":["265953387334128417533783229142107824643", "128925952502831700169030010272114177992", "138896328595853320761776874839011791774", "160616190006747144472108337585292575911", "228015238009796341240327091250876932018", "71600874674562408720298518993654728673", "59657049733372196380068050961988523682", "75882111226076295942487405329139410530", "64136458640941196898083386928760440656", "112513055506394179176074909462258007691", "198614634917747897042426569678831764695", "303560093868668070691232218874229168982", "203181757443446892219905689705187323361", "268289310753455125116496969042687087741", "128489441790955251978555926619893030340", "332085048172746370719374279780517669107", "304241201541386732293525466416520158958", "280933088920217115505016103242846997263", "161585619226953498893885346298666061327"], "threshold":0.9}, "id":"ASB-A-288896269-e792ac09", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/7444c007743970a9d6877c1b3fd2b28143687281", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationConversationInfo.java"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"14:0"}, {"fixed":"14:2023-12-01"}]}], "versions":["14"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/dd044a6cad393ea70440eef08c274b8a93b50202"], "severity":"High", "spl":"2023-12-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"275790296995513726427829673377107683482", "length":1576}, "id":"ASB-A-288896269-25c0bd7d", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/dd044a6cad393ea70440eef08c274b8a93b50202", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationConversationInfo.java", "function":"bindNotification"}}, {"deprecated":false, "digest":{"function_hash":"97586018491712111788720419061632568428", "length":1007}, "id":"ASB-A-288896269-7f0adca0", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/dd044a6cad393ea70440eef08c274b8a93b50202", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java", "function":"NotificationGutsManager"}}, {"deprecated":false, "digest":{"line_hashes":["250030163650702690218556814786070496467", "131310132713107569074546476544284301339", "200454172663836146017633787901049385944", "256631679654335705417997342968732696046", "60800081678460235282324025511543154992", "184029382496790418619655563721822200537", "144532002353641202108734101213349969251", "312432234744021497199616349711957352583", "299835800258771234386313081000909342564", "11251168981888847700427063204746697821", "3478132542860705786686384393193862126", "57957579615136433794160362532557502014", "216051915126484363564419485253569070130", "112219203957012154437837566026893687200", "167870209374219206177625039945305653474", "235885022108293952125383790887580950514", "94051001812651911373192909752203608523", "338111167483887221304864265345565092383", "93231106277635975303741366827246226731", "16238322785248966224942093181591361924"], "threshold":0.9}, "id":"ASB-A-288896269-8d2f55f8", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/dd044a6cad393ea70440eef08c274b8a93b50202", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java"}}, {"deprecated":false, "digest":{"function_hash":"277091814411092081832620044540052517237", "length":1596}, "id":"ASB-A-288896269-8fda8aa0", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/dd044a6cad393ea70440eef08c274b8a93b50202", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationGutsManager.java", "function":"initializeConversationNotificationInfo"}}, {"deprecated":false, "digest":{"line_hashes":["265953387334128417533783229142107824643", "128925952502831700169030010272114177992", "138896328595853320761776874839011791774", "160616190006747144472108337585292575911", "228015238009796341240327091250876932018", "71600874674562408720298518993654728673", "59657049733372196380068050961988523682", "194903749351548277678970832090882712657", "111501335088025618588057779761888179250", "305795497846898578712863349790280066572", "198614634917747897042426569678831764695", "33809323543126496807564377033955698641", "3061521919880570451099164147101699862", "268289310753455125116496969042687087741", "128489441790955251978555926619893030340", "332085048172746370719374279780517669107", "304241201541386732293525466416520158958", "280933088920217115505016103242846997263", "161585619226953498893885346298666061327"], "threshold":0.9}, "id":"ASB-A-288896269-9856de0e", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/dd044a6cad393ea70440eef08c274b8a93b50202", "target":{"file":"packages/SystemUI/src/com/android/systemui/statusbar/notification/row/NotificationConversationInfo.java"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2023-12-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/frameworks/base/+/d21ffbe8a2eeb2a5e6da7efbb1a0430ba6b022e0"}]}