In onCreate of SelectAccountActivity.java, there is a possible way to add contacts without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "65564356607277534436150172475175231106", "191796700634440559241015077184278445963", "281892994203818550334254604165202245383", "71885609132205396485296181628700741512", "104651787164578371536224819112459189469", "88593202937956494888005293644799818268", "165985182180417028789387494041434686673", "188367486637554207908560857786780417262", "182717922506615682891525769218125091764", "284003076085646647452777762808954884469", "249092255942031513079484402441123828186", "95886303725863482321449110670345318829" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/615666035723ff1828ff24674209012f30082de9", "target": { "file": "src/com/android/contacts/vcard/SelectAccountActivity.java" }, "id": "ASB-A-388032224-aec7a26d", "signature_type": "Line" }, { "digest": { "length": 1259.0, "function_hash": "293335654519794056458021428979007449916" }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/615666035723ff1828ff24674209012f30082de9", "target": { "file": "src/com/android/contacts/vcard/SelectAccountActivity.java", "function": "onCreate" }, "id": "ASB-A-388032224-cfaa3019", "signature_type": "Function" } ], "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Contacts/+/615666035723ff1828ff24674209012f30082de9" ], "spl": "2025-09-01" }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "65564356607277534436150172475175231106", "191796700634440559241015077184278445963", "281892994203818550334254604165202245383", "71885609132205396485296181628700741512", "104651787164578371536224819112459189469", "88593202937956494888005293644799818268", "165985182180417028789387494041434686673", "188367486637554207908560857786780417262", "182717922506615682891525769218125091764", "284003076085646647452777762808954884469", "249092255942031513079484402441123828186", "95886303725863482321449110670345318829" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/5484a98b668d6106cd8c857b5122cafec82a6644", "target": { "file": "src/com/android/contacts/vcard/SelectAccountActivity.java" }, "id": "ASB-A-388032224-a1654468", "signature_type": "Line" }, { "digest": { "length": 1259.0, "function_hash": "293335654519794056458021428979007449916" }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/5484a98b668d6106cd8c857b5122cafec82a6644", "target": { "file": "src/com/android/contacts/vcard/SelectAccountActivity.java", "function": "onCreate" }, "id": "ASB-A-388032224-a1de5820", "signature_type": "Function" } ], "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Contacts/+/5484a98b668d6106cd8c857b5122cafec82a6644" ], "spl": "2025-09-01" }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "65564356607277534436150172475175231106", "191796700634440559241015077184278445963", "281892994203818550334254604165202245383", "71885609132205396485296181628700741512", "104651787164578371536224819112459189469", "88593202937956494888005293644799818268", "165985182180417028789387494041434686673", "188367486637554207908560857786780417262", "182717922506615682891525769218125091764", "284003076085646647452777762808954884469", "249092255942031513079484402441123828186", "95886303725863482321449110670345318829" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/1dc140c0147d91384302dffcf072308855d69d21", "target": { "file": "src/com/android/contacts/vcard/SelectAccountActivity.java" }, "id": "ASB-A-388032224-d0092f75", "signature_type": "Line" }, { "digest": { "length": 1259.0, "function_hash": "293335654519794056458021428979007449916" }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/1dc140c0147d91384302dffcf072308855d69d21", "target": { "file": "src/com/android/contacts/vcard/SelectAccountActivity.java", "function": "onCreate" }, "id": "ASB-A-388032224-f545174a", "signature_type": "Function" } ], "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Contacts/+/1dc140c0147d91384302dffcf072308855d69d21" ], "spl": "2025-09-01" }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "65564356607277534436150172475175231106", "191796700634440559241015077184278445963", "281892994203818550334254604165202245383", "71885609132205396485296181628700741512", "104651787164578371536224819112459189469", "88593202937956494888005293644799818268", "165985182180417028789387494041434686673", "188367486637554207908560857786780417262", "182717922506615682891525769218125091764", "284003076085646647452777762808954884469", "249092255942031513079484402441123828186", "95886303725863482321449110670345318829" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/62aa0ca7cc36a6e79089b7f5b4409308c99359b5", "target": { "file": "src/com/android/contacts/vcard/SelectAccountActivity.java" }, "id": "ASB-A-388032224-5720e4ca", "signature_type": "Line" }, { "digest": { "length": 1346.0, "function_hash": "121884802074557384806285207887510377590" }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/62aa0ca7cc36a6e79089b7f5b4409308c99359b5", "target": { "file": "src/com/android/contacts/vcard/SelectAccountActivity.java", "function": "onCreate" }, "id": "ASB-A-388032224-6f25cf39", "signature_type": "Function" } ], "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Contacts/+/62aa0ca7cc36a6e79089b7f5b4409308c99359b5" ], "spl": "2025-09-01" }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "65564356607277534436150172475175231106", "191796700634440559241015077184278445963", "281892994203818550334254604165202245383", "71885609132205396485296181628700741512", "104651787164578371536224819112459189469", "88593202937956494888005293644799818268", "165985182180417028789387494041434686673", "188367486637554207908560857786780417262", "182717922506615682891525769218125091764", "284003076085646647452777762808954884469", "249092255942031513079484402441123828186", "95886303725863482321449110670345318829" ] }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/fd931e480d818d8decf2e8286293c5d62c484de1", "target": { "file": "src/com/android/contacts/vcard/SelectAccountActivity.java" }, "id": "ASB-A-388032224-53c5feba", "signature_type": "Line" }, { "digest": { "length": 1259.0, "function_hash": "293335654519794056458021428979007449916" }, "signature_version": "v1", "deprecated": false, "source": "https://android.googlesource.com/platform/packages/apps/Contacts/+/fd931e480d818d8decf2e8286293c5d62c484de1", "target": { "file": "src/com/android/contacts/vcard/SelectAccountActivity.java", "function": "onCreate" }, "id": "ASB-A-388032224-6f2068a6", "signature_type": "Function" } ], "severity": "High", "types": [ "EoP" ], "fixes": [ "https://android.googlesource.com/platform/packages/apps/Contacts/+/fd931e480d818d8decf2e8286293c5d62c484de1" ], "spl": "2025-09-01" }