In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "fixes": [ "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/bf66a79ddcd8d93f502bf908621469893f513780" ], "spl": "2025-03-01", "severity": "High", "vanir_signatures": [ { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/bf66a79ddcd8d93f502bf908621469893f513780", "target": { "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "11178458602711922477761236377671491738", "323964476593927769308130635745737529357", "198801690648515183445420070595674785819", "127124046656771281563741059096162754659", "212922888651005646510001940762947434719", "302796504643020493678420551773153536195", "158007238757640493293704202778375990501", "221550556625264261387627442779069723423", "104922033756251506235816196514269916351" ] }, "id": "ASB-A-304497167-05f72f23", "signature_version": "v1" }, { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/bf66a79ddcd8d93f502bf908621469893f513780", "target": { "function": "checkDownloadedFilePath", "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "length": 852.0, "function_hash": "151107043774485541674138510849676846659" }, "id": "ASB-A-304497167-e86f2d98", "signature_version": "v1" } ], "types": [ "ID" ] }
{ "fixes": [ "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e" ], "spl": "2025-03-01", "severity": "High", "vanir_signatures": [ { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e", "target": { "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "11178458602711922477761236377671491738", "323964476593927769308130635745737529357", "198801690648515183445420070595674785819", "127124046656771281563741059096162754659", "212922888651005646510001940762947434719", "302796504643020493678420551773153536195", "158007238757640493293704202778375990501", "221550556625264261387627442779069723423", "104922033756251506235816196514269916351" ] }, "id": "ASB-A-304497167-a253a0b7", "signature_version": "v1" }, { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e", "target": { "function": "checkDownloadedFilePath", "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "length": 852.0, "function_hash": "151107043774485541674138510849676846659" }, "id": "ASB-A-304497167-c9c90dd9", "signature_version": "v1" } ], "types": [ "ID" ] }
{ "fixes": [ "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e" ], "spl": "2025-03-01", "severity": "High", "vanir_signatures": [ { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e", "target": { "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "11178458602711922477761236377671491738", "323964476593927769308130635745737529357", "198801690648515183445420070595674785819", "127124046656771281563741059096162754659", "212922888651005646510001940762947434719", "302796504643020493678420551773153536195", "158007238757640493293704202778375990501", "221550556625264261387627442779069723423", "104922033756251506235816196514269916351" ] }, "id": "ASB-A-304497167-80e34c00", "signature_version": "v1" }, { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e", "target": { "function": "checkDownloadedFilePath", "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "length": 852.0, "function_hash": "151107043774485541674138510849676846659" }, "id": "ASB-A-304497167-e181120e", "signature_version": "v1" } ], "types": [ "ID" ] }
{ "fixes": [ "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/a2e3e8c7bec2b51f9192ca44757f170c0bde34a5" ], "spl": "2025-03-01", "severity": "High", "vanir_signatures": [ { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/a2e3e8c7bec2b51f9192ca44757f170c0bde34a5", "target": { "function": "checkDownloadedFilePath", "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "length": 852.0, "function_hash": "151107043774485541674138510849676846659" }, "id": "ASB-A-304497167-9ba3fa5e", "signature_version": "v1" }, { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/a2e3e8c7bec2b51f9192ca44757f170c0bde34a5", "target": { "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "11178458602711922477761236377671491738", "323964476593927769308130635745737529357", "198801690648515183445420070595674785819", "127124046656771281563741059096162754659", "212922888651005646510001940762947434719", "302796504643020493678420551773153536195", "158007238757640493293704202778375990501", "221550556625264261387627442779069723423", "104922033756251506235816196514269916351" ] }, "id": "ASB-A-304497167-9e21b710", "signature_version": "v1" } ], "types": [ "ID" ] }
{ "fixes": [ "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e" ], "spl": "2025-03-01", "severity": "High", "vanir_signatures": [ { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e", "target": { "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "11178458602711922477761236377671491738", "323964476593927769308130635745737529357", "198801690648515183445420070595674785819", "127124046656771281563741059096162754659", "212922888651005646510001940762947434719", "302796504643020493678420551773153536195", "158007238757640493293704202778375990501", "221550556625264261387627442779069723423", "104922033756251506235816196514269916351" ] }, "id": "ASB-A-304497167-7d273ba1", "signature_version": "v1" }, { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e", "target": { "function": "checkDownloadedFilePath", "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "length": 852.0, "function_hash": "151107043774485541674138510849676846659" }, "id": "ASB-A-304497167-8214e529", "signature_version": "v1" } ], "types": [ "ID" ] }
{ "fixes": [ "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e" ], "spl": "2025-03-01", "severity": "High", "vanir_signatures": [ { "signature_type": "Function", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e", "target": { "function": "checkDownloadedFilePath", "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "length": 852.0, "function_hash": "151107043774485541674138510849676846659" }, "id": "ASB-A-304497167-0e7bae2c", "signature_version": "v1" }, { "signature_type": "Line", "source": "https://android.googlesource.com/platform/packages/providers/DownloadProvider/+/7139559a207f7cfbabe86c143292042c3bf77d7e", "target": { "file": "src/com/android/providers/downloads/DownloadProvider.java" }, "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "11178458602711922477761236377671491738", "323964476593927769308130635745737529357", "198801690648515183445420070595674785819", "127124046656771281563741059096162754659", "212922888651005646510001940762947434719", "302796504643020493678420551773153536195", "158007238757640493293704202778375990501", "221550556625264261387627442779069723423", "104922033756251506235816196514269916351" ] }, "id": "ASB-A-304497167-4b7f6cc4", "signature_version": "v1" } ], "types": [ "ID" ] }