{"id":"PUB-A-224769956", "published":"2022-12-01T00:00:00Z", "modified":"2026-04-29T15:10:00.007170452Z", "aliases":["CVE-2022-20517", "A-224769956"], "details":"In getMessagesByPhoneNumber of MmsSmsProvider.java, there is a possible access to restricted tables due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "affected":[{"package":{"name":"platform/packages/providers/TelephonyProvider", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"13:0"}, {"fixed":"13:2022-12-01"}]}], "versions":["13"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f"], "severity":"Moderate", "spl":"2022-12-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"22422532387122491668667721950104656157", "length":1407}, "id":"PUB-A-224769956-33afdf62", "match_only_versions":["13"], "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f", "target":{"file":"src/com/android/providers/telephony/MmsSmsProvider.java", "function":"getMessagesByPhoneNumber"}}, {"deprecated":false, "digest":{"line_hashes":["258934897897631415745520717000714098069", "197014184272332667846658434605393915898", "246664981731303886033131157814483634983", "101001494901914073283465168712290708531", "40781936514460825829631966867885287527", "74775515332393555247263924237908194486", "71228892074586123301732053782579261311", "105011803168551978084127322986875381163", "137265764517892057556664940942374249360", "96700296200703501421605498402110971047", "204863617846661698942456037915140423870", "252949432377023224110765175983327207907", "277647244589725688428892329248863886364", "306605336572531699012372318475898263443", "169838437779391581360466352827228668039", "316756949732311853477928376052124049665", "76444377936777127146241846239546812827", "12758008060783028391415423680115144311", "151384020286346887885906492235622483531"], "threshold":0.9}, "id":"PUB-A-224769956-63b4c4c4", "match_only_versions":["13"], "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f", "target":{"file":"src/com/android/providers/telephony/MmsSmsProvider.java"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2022-12-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/packages/providers/TelephonyProvider/+/6d3d099d902a3c258972e46e4bc033f46b73109f"}]}