ASB-A-388032224

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-388032224.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-388032224
Aliases
  • A-388032224
  • CVE-2025-48523
Published
2025-09-01T00:00:00Z
Modified
2025-10-13T15:01:54.398779Z
Summary
[none]
Details

In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android

platform/packages/apps/Contacts

Package

Name
platform/packages/apps/Contacts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16-next:0
Fixed
16-next:2025-09-01

Affected versions

Other

16-next

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "65564356607277534436150172475175231106",
                    "191796700634440559241015077184278445963",
                    "281892994203818550334254604165202245383",
                    "71885609132205396485296181628700741512",
                    "104651787164578371536224819112459189469",
                    "88593202937956494888005293644799818268",
                    "165985182180417028789387494041434686673",
                    "188367486637554207908560857786780417262",
                    "182717922506615682891525769218125091764",
                    "284003076085646647452777762808954884469",
                    "249092255942031513079484402441123828186",
                    "95886303725863482321449110670345318829"
                ]
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/615666035723ff1828ff24674209012f30082de9",
            "target": {
                "file": "src/com/android/contacts/vcard/SelectAccountActivity.java"
            },
            "id": "ASB-A-388032224-aec7a26d",
            "signature_type": "Line"
        },
        {
            "digest": {
                "length": 1259.0,
                "function_hash": "293335654519794056458021428979007449916"
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/615666035723ff1828ff24674209012f30082de9",
            "target": {
                "file": "src/com/android/contacts/vcard/SelectAccountActivity.java",
                "function": "onCreate"
            },
            "id": "ASB-A-388032224-cfaa3019",
            "signature_type": "Function"
        }
    ],
    "severity": "High",
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/packages/apps/Contacts/+/615666035723ff1828ff24674209012f30082de9"
    ],
    "spl": "2025-09-01"
}

platform/packages/apps/Contacts

Package

Name
platform/packages/apps/Contacts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15:0
Fixed
15:2025-09-01

Affected versions

Other

15

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "65564356607277534436150172475175231106",
                    "191796700634440559241015077184278445963",
                    "281892994203818550334254604165202245383",
                    "71885609132205396485296181628700741512",
                    "104651787164578371536224819112459189469",
                    "88593202937956494888005293644799818268",
                    "165985182180417028789387494041434686673",
                    "188367486637554207908560857786780417262",
                    "182717922506615682891525769218125091764",
                    "284003076085646647452777762808954884469",
                    "249092255942031513079484402441123828186",
                    "95886303725863482321449110670345318829"
                ]
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/5484a98b668d6106cd8c857b5122cafec82a6644",
            "target": {
                "file": "src/com/android/contacts/vcard/SelectAccountActivity.java"
            },
            "id": "ASB-A-388032224-a1654468",
            "signature_type": "Line"
        },
        {
            "digest": {
                "length": 1259.0,
                "function_hash": "293335654519794056458021428979007449916"
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/5484a98b668d6106cd8c857b5122cafec82a6644",
            "target": {
                "file": "src/com/android/contacts/vcard/SelectAccountActivity.java",
                "function": "onCreate"
            },
            "id": "ASB-A-388032224-a1de5820",
            "signature_type": "Function"
        }
    ],
    "severity": "High",
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/packages/apps/Contacts/+/5484a98b668d6106cd8c857b5122cafec82a6644"
    ],
    "spl": "2025-09-01"
}

platform/packages/apps/Contacts

Package

Name
platform/packages/apps/Contacts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16:0
Fixed
16:2025-09-01

Affected versions

Other

16

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "65564356607277534436150172475175231106",
                    "191796700634440559241015077184278445963",
                    "281892994203818550334254604165202245383",
                    "71885609132205396485296181628700741512",
                    "104651787164578371536224819112459189469",
                    "88593202937956494888005293644799818268",
                    "165985182180417028789387494041434686673",
                    "188367486637554207908560857786780417262",
                    "182717922506615682891525769218125091764",
                    "284003076085646647452777762808954884469",
                    "249092255942031513079484402441123828186",
                    "95886303725863482321449110670345318829"
                ]
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/1dc140c0147d91384302dffcf072308855d69d21",
            "target": {
                "file": "src/com/android/contacts/vcard/SelectAccountActivity.java"
            },
            "id": "ASB-A-388032224-d0092f75",
            "signature_type": "Line"
        },
        {
            "digest": {
                "length": 1259.0,
                "function_hash": "293335654519794056458021428979007449916"
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/1dc140c0147d91384302dffcf072308855d69d21",
            "target": {
                "file": "src/com/android/contacts/vcard/SelectAccountActivity.java",
                "function": "onCreate"
            },
            "id": "ASB-A-388032224-f545174a",
            "signature_type": "Function"
        }
    ],
    "severity": "High",
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/packages/apps/Contacts/+/1dc140c0147d91384302dffcf072308855d69d21"
    ],
    "spl": "2025-09-01"
}

platform/packages/apps/Contacts

Package

Name
platform/packages/apps/Contacts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13:0
Fixed
13:2025-09-01

Affected versions

Other

13

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "65564356607277534436150172475175231106",
                    "191796700634440559241015077184278445963",
                    "281892994203818550334254604165202245383",
                    "71885609132205396485296181628700741512",
                    "104651787164578371536224819112459189469",
                    "88593202937956494888005293644799818268",
                    "165985182180417028789387494041434686673",
                    "188367486637554207908560857786780417262",
                    "182717922506615682891525769218125091764",
                    "284003076085646647452777762808954884469",
                    "249092255942031513079484402441123828186",
                    "95886303725863482321449110670345318829"
                ]
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/62aa0ca7cc36a6e79089b7f5b4409308c99359b5",
            "target": {
                "file": "src/com/android/contacts/vcard/SelectAccountActivity.java"
            },
            "id": "ASB-A-388032224-5720e4ca",
            "signature_type": "Line"
        },
        {
            "digest": {
                "length": 1346.0,
                "function_hash": "121884802074557384806285207887510377590"
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/62aa0ca7cc36a6e79089b7f5b4409308c99359b5",
            "target": {
                "file": "src/com/android/contacts/vcard/SelectAccountActivity.java",
                "function": "onCreate"
            },
            "id": "ASB-A-388032224-6f25cf39",
            "signature_type": "Function"
        }
    ],
    "severity": "High",
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/packages/apps/Contacts/+/62aa0ca7cc36a6e79089b7f5b4409308c99359b5"
    ],
    "spl": "2025-09-01"
}

platform/packages/apps/Contacts

Package

Name
platform/packages/apps/Contacts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14:0
Fixed
14:2025-09-01

Affected versions

Other

14

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "65564356607277534436150172475175231106",
                    "191796700634440559241015077184278445963",
                    "281892994203818550334254604165202245383",
                    "71885609132205396485296181628700741512",
                    "104651787164578371536224819112459189469",
                    "88593202937956494888005293644799818268",
                    "165985182180417028789387494041434686673",
                    "188367486637554207908560857786780417262",
                    "182717922506615682891525769218125091764",
                    "284003076085646647452777762808954884469",
                    "249092255942031513079484402441123828186",
                    "95886303725863482321449110670345318829"
                ]
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/fd931e480d818d8decf2e8286293c5d62c484de1",
            "target": {
                "file": "src/com/android/contacts/vcard/SelectAccountActivity.java"
            },
            "id": "ASB-A-388032224-53c5feba",
            "signature_type": "Line"
        },
        {
            "digest": {
                "length": 1259.0,
                "function_hash": "293335654519794056458021428979007449916"
            },
            "signature_version": "v1",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/fd931e480d818d8decf2e8286293c5d62c484de1",
            "target": {
                "file": "src/com/android/contacts/vcard/SelectAccountActivity.java",
                "function": "onCreate"
            },
            "id": "ASB-A-388032224-6f2068a6",
            "signature_type": "Function"
        }
    ],
    "severity": "High",
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/packages/apps/Contacts/+/fd931e480d818d8decf2e8286293c5d62c484de1"
    ],
    "spl": "2025-09-01"
}