ASB-A-404252173

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-404252173.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-404252173
Aliases
Published
2025-09-01T00:00:00Z
Modified
2026-03-14T08:46:42.661861Z
Summary
[none]
Details

In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16-next:0
Fixed
16-next:2025-09-01

Affected versions

Other
16-next

Ecosystem specific

{
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/14f874decfdd5616b9fb3804154dd2560ebad0a1"
    ],
    "spl": "2025-09-01",
    "vanir_signatures": [
        {
            "source": "https://android.googlesource.com/platform/frameworks/base/+/14f874decfdd5616b9fb3804154dd2560ebad0a1",
            "deprecated": false,
            "signature_version": "v1",
            "id": "ASB-A-404252173-7cb6b91c",
            "digest": {
                "length": 469.0,
                "function_hash": "53110976986727826745012391277412001162"
            },
            "signature_type": "Function",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java",
                "function": "showDismissibleKeyguard"
            }
        },
        {
            "source": "https://android.googlesource.com/platform/frameworks/base/+/14f874decfdd5616b9fb3804154dd2560ebad0a1",
            "deprecated": false,
            "signature_version": "v1",
            "id": "ASB-A-404252173-8561bd37",
            "digest": {
                "length": 1235.0,
                "function_hash": "319673732979670559273932594517585439603"
            },
            "signature_type": "Function",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java",
                "function": "KeyguardService"
            }
        },
        {
            "source": "https://android.googlesource.com/platform/frameworks/base/+/14f874decfdd5616b9fb3804154dd2560ebad0a1",
            "deprecated": false,
            "signature_version": "v1",
            "id": "ASB-A-404252173-f35fcc83",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "299762013212905261322887212060684968711",
                    "2190103179571531646118732716786892301",
                    "10537140773852501480760427689120542655",
                    "215508457842688850767876439392392243095",
                    "273904484769780814852636855735957655305",
                    "198904980846135239138008202747651082760",
                    "131549019979372352019073056993524637149",
                    "299038505897963556330320920719571674613",
                    "171090511766624527407214502187956764901",
                    "120174323833532896976944042787342744943",
                    "252266292509362318653387765667842328546",
                    "108420304567526705932591944887557447711",
                    "22507195533739256989426653925545736023",
                    "175129239960513559978030496938510201289",
                    "59643440053343347558642716143813228323",
                    "266467421320682859761296962874588168303",
                    "114763453852314145694939385375158225766"
                ]
            },
            "signature_type": "Line",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            }
        }
    ],
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-404252173.json"

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15:0
Fixed
15:2025-09-01

Affected versions

Other
15

Ecosystem specific

{
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/1de2b4bc46b790bd415cf0d09e17af766382db83"
    ],
    "spl": "2025-09-01",
    "vanir_signatures": [
        {
            "source": "https://android.googlesource.com/platform/frameworks/base/+/1de2b4bc46b790bd415cf0d09e17af766382db83",
            "deprecated": false,
            "signature_version": "v1",
            "id": "ASB-A-404252173-7c4f55ca",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "67463914258819881945036457889354861897",
                    "313162232528710765721358036441381930075",
                    "60741893716015284408742493138543983060",
                    "223954356135584472322304142492918315338",
                    "188088051636725881587366746998127718408",
                    "152687359640194369127572195210192741057",
                    "294134430072931070783241566105918495466",
                    "327350491587318439954200447247129110486",
                    "75323225607535387655798458110284671492",
                    "76476322412690229110274796919526277633",
                    "163017639620719605693164298867149258369",
                    "224879454754417578960454354212612459393",
                    "22507195533739256989426653925545736023",
                    "59961919104088190861660269655859843094",
                    "100099234157792401984734694015238810214",
                    "153378952447524765849198707575339650078"
                ]
            },
            "signature_type": "Line",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            }
        },
        {
            "source": "https://android.googlesource.com/platform/frameworks/base/+/1de2b4bc46b790bd415cf0d09e17af766382db83",
            "deprecated": false,
            "signature_version": "v1",
            "id": "ASB-A-404252173-85a6e95c",
            "digest": {
                "length": 842.0,
                "function_hash": "99788198260370255432130355245670274726"
            },
            "signature_type": "Function",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java",
                "function": "KeyguardService"
            }
        },
        {
            "source": "https://android.googlesource.com/platform/frameworks/base/+/1de2b4bc46b790bd415cf0d09e17af766382db83",
            "deprecated": false,
            "signature_version": "v1",
            "id": "ASB-A-404252173-a39fd387",
            "digest": {
                "length": 373.0,
                "function_hash": "101160497034016159186143360875995385371"
            },
            "signature_type": "Function",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java",
                "function": "showDismissibleKeyguard"
            }
        }
    ],
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-404252173.json"

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16:0
Fixed
16:2025-09-01

Affected versions

Other
16

Ecosystem specific

{
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/71cb04bbbe0c6c9a07ad4f11fff1253fa480cbdc"
    ],
    "spl": "2025-09-01",
    "vanir_signatures": [
        {
            "source": "https://android.googlesource.com/platform/frameworks/base/+/71cb04bbbe0c6c9a07ad4f11fff1253fa480cbdc",
            "deprecated": false,
            "signature_version": "v1",
            "id": "ASB-A-404252173-19153a7e",
            "digest": {
                "length": 593.0,
                "function_hash": "110523820707884031120745551694318071263"
            },
            "signature_type": "Function",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java",
                "function": "showDismissibleKeyguard"
            }
        },
        {
            "source": "https://android.googlesource.com/platform/frameworks/base/+/71cb04bbbe0c6c9a07ad4f11fff1253fa480cbdc",
            "deprecated": false,
            "signature_version": "v1",
            "id": "ASB-A-404252173-2bd4d17c",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "328705736549937340018465320626372623490",
                    "2498621061006664823077301845240727374",
                    "10537140773852501480760427689120542655",
                    "215508457842688850767876439392392243095",
                    "273904484769780814852636855735957655305",
                    "198904980846135239138008202747651082760",
                    "131549019979372352019073056993524637149",
                    "299038505897963556330320920719571674613",
                    "171090511766624527407214502187956764901",
                    "120174323833532896976944042787342744943",
                    "252266292509362318653387765667842328546",
                    "108420304567526705932591944887557447711",
                    "22507195533739256989426653925545736023",
                    "292114082995795596172871128308698869466",
                    "234121922515277664258585958316132089912",
                    "257657618865946147205540833728478584068"
                ]
            },
            "signature_type": "Line",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            }
        },
        {
            "source": "https://android.googlesource.com/platform/frameworks/base/+/71cb04bbbe0c6c9a07ad4f11fff1253fa480cbdc",
            "deprecated": false,
            "signature_version": "v1",
            "id": "ASB-A-404252173-6013d74e",
            "digest": {
                "length": 1235.0,
                "function_hash": "319673732979670559273932594517585439603"
            },
            "signature_type": "Function",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java",
                "function": "KeyguardService"
            }
        }
    ],
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-404252173.json"