ASB-A-378514614

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-378514614.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-378514614
Aliases
  • A-378514614
  • CVE-2025-26428
Published
2025-05-01T00:00:00Z
Modified
2025-10-13T15:01:54.398779Z
Summary
[none]
Details

In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

References

Affected packages

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15-next:0
Fixed
15-next:2025-05-01

Affected versions

Other

15-next

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "length": 1010.0,
                "function_hash": "68881114488809255880383061169506138695"
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/frameworks/base/+/b4945cf98c97121821c178713a613a6a6e830c3a",
            "target": {
                "file": "services/core/java/com/android/server/wm/LockTaskController.java",
                "function": "startLockTaskMode"
            },
            "id": "ASB-A-378514614-3bd6b408",
            "signature_type": "Function"
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "293398859358425972583020354542497483819",
                    "80467941493554904999700164977590972935",
                    "7513061549015014267534802234056735246",
                    "217315157243660948969603039651018798690"
                ]
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/frameworks/base/+/b4945cf98c97121821c178713a613a6a6e830c3a",
            "target": {
                "file": "services/core/java/com/android/server/wm/LockTaskController.java"
            },
            "id": "ASB-A-378514614-f5b62ae3",
            "signature_type": "Line"
        }
    ],
    "severity": "High",
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/b4945cf98c97121821c178713a613a6a6e830c3a"
    ],
    "spl": "2025-05-01"
}

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15:0
Fixed
15:2025-05-01

Affected versions

Other

15

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "293398859358425972583020354542497483819",
                    "80467941493554904999700164977590972935",
                    "7513061549015014267534802234056735246",
                    "217315157243660948969603039651018798690"
                ]
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/frameworks/base/+/d5268b9953765352dac09179e10836c6e481e266",
            "target": {
                "file": "services/core/java/com/android/server/wm/LockTaskController.java"
            },
            "id": "ASB-A-378514614-956674a0",
            "signature_type": "Line"
        },
        {
            "digest": {
                "length": 992.0,
                "function_hash": "150286947850126248415288695409838541637"
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/frameworks/base/+/d5268b9953765352dac09179e10836c6e481e266",
            "target": {
                "file": "services/core/java/com/android/server/wm/LockTaskController.java",
                "function": "startLockTaskMode"
            },
            "id": "ASB-A-378514614-bb86b438",
            "signature_type": "Function"
        }
    ],
    "severity": "High",
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/d5268b9953765352dac09179e10836c6e481e266"
    ],
    "spl": "2025-05-01"
}

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13:0
Fixed
13:2025-05-01

Affected versions

Other

13

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "30164921329345463907376268405083112938",
                    "80467941493554904999700164977590972935",
                    "7513061549015014267534802234056735246",
                    "217315157243660948969603039651018798690"
                ]
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/frameworks/base/+/a3240bf2ba1587b808b4314dd2e32c624b57c8da",
            "target": {
                "file": "services/core/java/com/android/server/wm/LockTaskController.java"
            },
            "id": "ASB-A-378514614-533147e1",
            "signature_type": "Line"
        },
        {
            "digest": {
                "length": 580.0,
                "function_hash": "191887681608595310044475575209842618885"
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/frameworks/base/+/a3240bf2ba1587b808b4314dd2e32c624b57c8da",
            "target": {
                "file": "services/core/java/com/android/server/wm/LockTaskController.java",
                "function": "startLockTaskMode"
            },
            "id": "ASB-A-378514614-c9e99fce",
            "signature_type": "Function"
        }
    ],
    "severity": "High",
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/a3240bf2ba1587b808b4314dd2e32c624b57c8da"
    ],
    "spl": "2025-05-01"
}

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14:0
Fixed
14:2025-05-01

Affected versions

Other

14

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "30164921329345463907376268405083112938",
                    "80467941493554904999700164977590972935",
                    "7513061549015014267534802234056735246",
                    "217315157243660948969603039651018798690"
                ]
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/frameworks/base/+/a3240bf2ba1587b808b4314dd2e32c624b57c8da",
            "target": {
                "file": "services/core/java/com/android/server/wm/LockTaskController.java"
            },
            "id": "ASB-A-378514614-6536628b",
            "signature_type": "Line"
        },
        {
            "digest": {
                "length": 580.0,
                "function_hash": "191887681608595310044475575209842618885"
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/frameworks/base/+/a3240bf2ba1587b808b4314dd2e32c624b57c8da",
            "target": {
                "file": "services/core/java/com/android/server/wm/LockTaskController.java",
                "function": "startLockTaskMode"
            },
            "id": "ASB-A-378514614-fce2ab59",
            "signature_type": "Function"
        }
    ],
    "severity": "High",
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/a3240bf2ba1587b808b4314dd2e32c624b57c8da"
    ],
    "spl": "2025-05-01"
}