In onNullBinding of RemoteFillService.java, there is a possible background activity launch due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/d883efa912c0a39c46437074576cffb7078ac455"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/d883efa912c0a39c46437074576cffb7078ac455",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-401545800-54e1a5a5",
"digest": {
"threshold": 0.9,
"line_hashes": [
"211598700065759576457031615535262198756",
"155749383717225277394767495477347620741",
"326208054660854204827188902700841952735"
]
},
"signature_type": "Line",
"target": {
"file": "services/autofill/java/com/android/server/autofill/RemoteFillService.java"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/0cbc42f4dc6b3763532176b67141aac0c8a400d7"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/0cbc42f4dc6b3763532176b67141aac0c8a400d7",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-401545800-4b720817",
"digest": {
"threshold": 0.9,
"line_hashes": [
"211598700065759576457031615535262198756",
"155749383717225277394767495477347620741",
"326208054660854204827188902700841952735"
]
},
"signature_type": "Line",
"target": {
"file": "services/autofill/java/com/android/server/autofill/RemoteFillService.java"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/857a29c6a368906a7502be5caaa910ef61dcb54c"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/857a29c6a368906a7502be5caaa910ef61dcb54c",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-401545800-7fbf8d20",
"digest": {
"threshold": 0.9,
"line_hashes": [
"211598700065759576457031615535262198756",
"155749383717225277394767495477347620741",
"326208054660854204827188902700841952735"
]
},
"signature_type": "Line",
"target": {
"file": "services/autofill/java/com/android/server/autofill/RemoteFillService.java"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/2f90ae5465282498eed99a4dcaddb4494e69743b"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/2f90ae5465282498eed99a4dcaddb4494e69743b",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-401545800-bb9fd62e",
"digest": {
"threshold": 0.9,
"line_hashes": [
"211598700065759576457031615535262198756",
"155749383717225277394767495477347620741",
"326208054660854204827188902700841952735"
]
},
"signature_type": "Line",
"target": {
"file": "services/autofill/java/com/android/server/autofill/RemoteFillService.java"
}
}
],
"severity": "High"
}{
"types": [
"EoP"
],
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/cd1b8b60cd9b58a221ac06b2483ca7d49c2f1787"
],
"spl": "2025-09-01",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/platform/frameworks/base/+/cd1b8b60cd9b58a221ac06b2483ca7d49c2f1787",
"deprecated": false,
"signature_version": "v1",
"id": "ASB-A-401545800-69ef838c",
"digest": {
"threshold": 0.9,
"line_hashes": [
"211598700065759576457031615535262198756",
"155749383717225277394767495477347620741",
"326208054660854204827188902700841952735"
]
},
"signature_type": "Line",
"target": {
"file": "services/autofill/java/com/android/server/autofill/RemoteFillService.java"
}
}
],
"severity": "High"
}