In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "severity": "High", "types": [ "ID" ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823" ], "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Function", "target": { "file": "libs/androidfw/CursorWindow.cpp", "function": "CursorWindow::create" }, "deprecated": false, "digest": { "length": 539.0, "function_hash": "254295238308086076035495037435727539914" }, "id": "ASB-A-309407957-21a5757e", "source": "https://android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "libs/androidfw/CursorWindow.cpp" }, "deprecated": false, "digest": { "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ], "threshold": 0.9 }, "id": "ASB-A-309407957-e5a135d2", "source": "https://android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823" } ], "spl": "2025-06-01" }
{ "severity": "High", "types": [ "ID" ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef" ], "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Line", "target": { "file": "libs/androidfw/CursorWindow.cpp" }, "deprecated": false, "digest": { "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ], "threshold": 0.9 }, "id": "ASB-A-309407957-10158c9d", "source": "https://android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "libs/androidfw/CursorWindow.cpp", "function": "CursorWindow::create" }, "deprecated": false, "digest": { "length": 539.0, "function_hash": "254295238308086076035495037435727539914" }, "id": "ASB-A-309407957-1cac09cf", "source": "https://android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef" } ], "spl": "2025-06-01" }
{ "severity": "High", "types": [ "ID" ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958" ], "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Function", "target": { "file": "libs/androidfw/CursorWindow.cpp", "function": "CursorWindow::create" }, "deprecated": false, "digest": { "length": 539.0, "function_hash": "254295238308086076035495037435727539914" }, "id": "ASB-A-309407957-4361cfde", "source": "https://android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958" }, { "signature_version": "v1", "signature_type": "Line", "target": { "file": "libs/androidfw/CursorWindow.cpp" }, "deprecated": false, "digest": { "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ], "threshold": 0.9 }, "id": "ASB-A-309407957-ed2703fc", "source": "https://android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958" } ], "spl": "2025-06-01" }
{ "severity": "High", "types": [ "ID" ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613" ], "vanir_signatures": [ { "signature_version": "v1", "signature_type": "Line", "target": { "file": "libs/androidfw/CursorWindow.cpp" }, "deprecated": false, "digest": { "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ], "threshold": 0.9 }, "id": "ASB-A-309407957-df957ada", "source": "https://android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613" }, { "signature_version": "v1", "signature_type": "Function", "target": { "file": "libs/androidfw/CursorWindow.cpp", "function": "CursorWindow::create" }, "deprecated": false, "digest": { "length": 539.0, "function_hash": "254295238308086076035495037435727539914" }, "id": "ASB-A-309407957-e80897c8", "source": "https://android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613" } ], "spl": "2025-06-01" }