In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Contacts/+/615666035723ff1828ff24674209012f30082de9"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/615666035723ff1828ff24674209012f30082de9",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388032224-aec7a26d",
"digest": {
"threshold": 0.9,
"line_hashes": [
"65564356607277534436150172475175231106",
"191796700634440559241015077184278445963",
"281892994203818550334254604165202245383",
"71885609132205396485296181628700741512",
"104651787164578371536224819112459189469",
"88593202937956494888005293644799818268",
"165985182180417028789387494041434686673",
"188367486637554207908560857786780417262",
"182717922506615682891525769218125091764",
"284003076085646647452777762808954884469",
"249092255942031513079484402441123828186",
"95886303725863482321449110670345318829"
]
},
"signature_type": "Line",
"target": {
"file": "src/com/android/contacts/vcard/SelectAccountActivity.java"
}
},
{
"source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/615666035723ff1828ff24674209012f30082de9",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388032224-cfaa3019",
"digest": {
"length": 1259.0,
"function_hash": "293335654519794056458021428979007449916"
},
"signature_type": "Function",
"target": {
"file": "src/com/android/contacts/vcard/SelectAccountActivity.java",
"function": "onCreate"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Contacts/+/5484a98b668d6106cd8c857b5122cafec82a6644"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/5484a98b668d6106cd8c857b5122cafec82a6644",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388032224-a1654468",
"digest": {
"threshold": 0.9,
"line_hashes": [
"65564356607277534436150172475175231106",
"191796700634440559241015077184278445963",
"281892994203818550334254604165202245383",
"71885609132205396485296181628700741512",
"104651787164578371536224819112459189469",
"88593202937956494888005293644799818268",
"165985182180417028789387494041434686673",
"188367486637554207908560857786780417262",
"182717922506615682891525769218125091764",
"284003076085646647452777762808954884469",
"249092255942031513079484402441123828186",
"95886303725863482321449110670345318829"
]
},
"signature_type": "Line",
"target": {
"file": "src/com/android/contacts/vcard/SelectAccountActivity.java"
}
},
{
"source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/5484a98b668d6106cd8c857b5122cafec82a6644",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388032224-a1de5820",
"digest": {
"length": 1259.0,
"function_hash": "293335654519794056458021428979007449916"
},
"signature_type": "Function",
"target": {
"file": "src/com/android/contacts/vcard/SelectAccountActivity.java",
"function": "onCreate"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Contacts/+/1dc140c0147d91384302dffcf072308855d69d21"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/1dc140c0147d91384302dffcf072308855d69d21",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388032224-d0092f75",
"digest": {
"threshold": 0.9,
"line_hashes": [
"65564356607277534436150172475175231106",
"191796700634440559241015077184278445963",
"281892994203818550334254604165202245383",
"71885609132205396485296181628700741512",
"104651787164578371536224819112459189469",
"88593202937956494888005293644799818268",
"165985182180417028789387494041434686673",
"188367486637554207908560857786780417262",
"182717922506615682891525769218125091764",
"284003076085646647452777762808954884469",
"249092255942031513079484402441123828186",
"95886303725863482321449110670345318829"
]
},
"signature_type": "Line",
"target": {
"file": "src/com/android/contacts/vcard/SelectAccountActivity.java"
}
},
{
"source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/1dc140c0147d91384302dffcf072308855d69d21",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388032224-f545174a",
"digest": {
"length": 1259.0,
"function_hash": "293335654519794056458021428979007449916"
},
"signature_type": "Function",
"target": {
"file": "src/com/android/contacts/vcard/SelectAccountActivity.java",
"function": "onCreate"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Contacts/+/62aa0ca7cc36a6e79089b7f5b4409308c99359b5"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/62aa0ca7cc36a6e79089b7f5b4409308c99359b5",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388032224-5720e4ca",
"digest": {
"threshold": 0.9,
"line_hashes": [
"65564356607277534436150172475175231106",
"191796700634440559241015077184278445963",
"281892994203818550334254604165202245383",
"71885609132205396485296181628700741512",
"104651787164578371536224819112459189469",
"88593202937956494888005293644799818268",
"165985182180417028789387494041434686673",
"188367486637554207908560857786780417262",
"182717922506615682891525769218125091764",
"284003076085646647452777762808954884469",
"249092255942031513079484402441123828186",
"95886303725863482321449110670345318829"
]
},
"signature_type": "Line",
"target": {
"file": "src/com/android/contacts/vcard/SelectAccountActivity.java"
}
},
{
"source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/62aa0ca7cc36a6e79089b7f5b4409308c99359b5",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388032224-6f25cf39",
"digest": {
"length": 1346.0,
"function_hash": "121884802074557384806285207887510377590"
},
"signature_type": "Function",
"target": {
"file": "src/com/android/contacts/vcard/SelectAccountActivity.java",
"function": "onCreate"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/packages/apps/Contacts/+/fd931e480d818d8decf2e8286293c5d62c484de1"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/fd931e480d818d8decf2e8286293c5d62c484de1",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388032224-53c5feba",
"digest": {
"threshold": 0.9,
"line_hashes": [
"65564356607277534436150172475175231106",
"191796700634440559241015077184278445963",
"281892994203818550334254604165202245383",
"71885609132205396485296181628700741512",
"104651787164578371536224819112459189469",
"88593202937956494888005293644799818268",
"165985182180417028789387494041434686673",
"188367486637554207908560857786780417262",
"182717922506615682891525769218125091764",
"284003076085646647452777762808954884469",
"249092255942031513079484402441123828186",
"95886303725863482321449110670345318829"
]
},
"signature_type": "Line",
"target": {
"file": "src/com/android/contacts/vcard/SelectAccountActivity.java"
}
},
{
"source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/fd931e480d818d8decf2e8286293c5d62c484de1",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-388032224-6f2068a6",
"digest": {
"length": 1259.0,
"function_hash": "293335654519794056458021428979007449916"
},
"signature_type": "Function",
"target": {
"file": "src/com/android/contacts/vcard/SelectAccountActivity.java",
"function": "onCreate"
}
}
],
"severity": "High"
}