In onCreate of ChooserActivity.java , there is a possible way to view other users' images due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 6244.0, "function_hash": "336671546719732193332363639853093470883" }, "id": "ASB-A-277207798-131c4ed5", "source": "https://android.googlesource.com/platform/frameworks/base/+/bad47a2280c7107e1213f4adc5a3825a62698d00", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/ChooserActivity.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "253726217667786760008791040528132999656", "228422336533060252731829592399006004338", "335424932981330831523731482027422461698", "45605471419092542802268726131796893831", "231196650600773283353027740648307444990", "13750646095156668772480085108097034858", "46688699789534617252032762653797350857", "76484926273318022941110547313781106396", "319801971747590014370831222802487791519", "225167580596828937992821877251436851634", "130607908879052246674719283887525476671", "153132771818589155319113541875463098830", "99776271114638537866965957305766270641", "205008932327429738391762413441071538873", "290436820296095206163711891884675157053", "107881527603548020291656350860705051943", "76647954778615471049259555882753692194", "80810554446883258785855333051732088581", "338282417515360549291114073952096767125", "194786844876987425545005515131039931828", "260328569219012495242470606039928699047", "13631907288037037077954071872415923239", "75662308371422950237069767970774920254" ] }, "id": "ASB-A-277207798-60b7353a", "source": "https://android.googlesource.com/platform/frameworks/base/+/bad47a2280c7107e1213f4adc5a3825a62698d00", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/ChooserActivity.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/bad47a2280c7107e1213f4adc5a3825a62698d00" ], "spl": "2025-04-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 6212.0, "function_hash": "175854063412095478767692237294382957975" }, "id": "ASB-A-277207798-3670a072", "source": "https://android.googlesource.com/platform/frameworks/base/+/e73bb60fed12daa78ddad8308b31b0c78f1c3c66", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/ChooserActivity.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "41390077426975099314374087252517731925", "45681176917284083586723022694067938350", "333957807868229023926107419401633699128", "102431590296808685158151479537038954109", "26172496286527130508864160995380617790", "319801971747590014370831222802487791519", "225167580596828937992821877251436851634", "130607908879052246674719283887525476671", "153132771818589155319113541875463098830", "99776271114638537866965957305766270641", "205008932327429738391762413441071538873", "290436820296095206163711891884675157053", "107881527603548020291656350860705051943", "76647954778615471049259555882753692194", "80810554446883258785855333051732088581", "338282417515360549291114073952096767125", "194786844876987425545005515131039931828", "260328569219012495242470606039928699047", "13631907288037037077954071872415923239", "75662308371422950237069767970774920254" ] }, "id": "ASB-A-277207798-73ae919f", "source": "https://android.googlesource.com/platform/frameworks/base/+/e73bb60fed12daa78ddad8308b31b0c78f1c3c66", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/ChooserActivity.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/e73bb60fed12daa78ddad8308b31b0c78f1c3c66" ], "spl": "2025-04-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 6244.0, "function_hash": "336671546719732193332363639853093470883" }, "id": "ASB-A-277207798-471c5d8a", "source": "https://android.googlesource.com/platform/frameworks/base/+/bad47a2280c7107e1213f4adc5a3825a62698d00", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/ChooserActivity.java", "function": "onCreate" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "253726217667786760008791040528132999656", "228422336533060252731829592399006004338", "335424932981330831523731482027422461698", "45605471419092542802268726131796893831", "231196650600773283353027740648307444990", "13750646095156668772480085108097034858", "46688699789534617252032762653797350857", "76484926273318022941110547313781106396", "319801971747590014370831222802487791519", "225167580596828937992821877251436851634", "130607908879052246674719283887525476671", "153132771818589155319113541875463098830", "99776271114638537866965957305766270641", "205008932327429738391762413441071538873", "290436820296095206163711891884675157053", "107881527603548020291656350860705051943", "76647954778615471049259555882753692194", "80810554446883258785855333051732088581", "338282417515360549291114073952096767125", "194786844876987425545005515131039931828", "260328569219012495242470606039928699047", "13631907288037037077954071872415923239", "75662308371422950237069767970774920254" ] }, "id": "ASB-A-277207798-c63bbe57", "source": "https://android.googlesource.com/platform/frameworks/base/+/bad47a2280c7107e1213f4adc5a3825a62698d00", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/com/android/internal/app/ChooserActivity.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/bad47a2280c7107e1213f4adc5a3825a62698d00" ], "spl": "2025-04-01", "severity": "High", "types": [ "EoP" ] }