In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "types": [ "ID" ], "severity": "High", "vanir_signatures": [ { "digest": { "function_hash": "254295238308086076035495037435727539914", "length": 539.0 }, "id": "ASB-A-309407957-21a5757e", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823", "signature_version": "v1", "signature_type": "Function", "target": { "file": "libs/androidfw/CursorWindow.cpp", "function": "CursorWindow::create" } }, { "digest": { "threshold": 0.9, "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ] }, "id": "ASB-A-309407957-e5a135d2", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823", "signature_version": "v1", "signature_type": "Line", "target": { "file": "libs/androidfw/CursorWindow.cpp" } } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823" ], "spl": "2025-06-01" }
{ "types": [ "ID" ], "severity": "High", "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ] }, "id": "ASB-A-309407957-10158c9d", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef", "signature_version": "v1", "signature_type": "Line", "target": { "file": "libs/androidfw/CursorWindow.cpp" } }, { "digest": { "function_hash": "254295238308086076035495037435727539914", "length": 539.0 }, "id": "ASB-A-309407957-1cac09cf", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef", "signature_version": "v1", "signature_type": "Function", "target": { "file": "libs/androidfw/CursorWindow.cpp", "function": "CursorWindow::create" } } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef" ], "spl": "2025-06-01" }
{ "types": [ "ID" ], "severity": "High", "vanir_signatures": [ { "digest": { "function_hash": "254295238308086076035495037435727539914", "length": 539.0 }, "id": "ASB-A-309407957-4361cfde", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958", "signature_version": "v1", "signature_type": "Function", "target": { "file": "libs/androidfw/CursorWindow.cpp", "function": "CursorWindow::create" } }, { "digest": { "threshold": 0.9, "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ] }, "id": "ASB-A-309407957-ed2703fc", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958", "signature_version": "v1", "signature_type": "Line", "target": { "file": "libs/androidfw/CursorWindow.cpp" } } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958" ], "spl": "2025-06-01" }
{ "types": [ "ID" ], "severity": "High", "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ] }, "id": "ASB-A-309407957-df957ada", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613", "signature_version": "v1", "signature_type": "Line", "target": { "file": "libs/androidfw/CursorWindow.cpp" } }, { "digest": { "function_hash": "254295238308086076035495037435727539914", "length": 539.0 }, "id": "ASB-A-309407957-e80897c8", "deprecated": false, "source": "https://android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613", "signature_version": "v1", "signature_type": "Function", "target": { "file": "libs/androidfw/CursorWindow.cpp", "function": "CursorWindow::create" } } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613" ], "spl": "2025-06-01" }