ASB-A-404252173

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-404252173.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-404252173
Aliases
Published
2025-09-01T00:00:00Z
Modified
2026-04-17T15:55:28.020024Z
Summary
[none]
Details

In showDismissibleKeyguard of KeyguardService.java, there is a possible way to bypass app pinning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16-next:0
Fixed
16-next:2025-09-01

Affected versions

Other
16-next

Ecosystem specific

{
    "severity": "High",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/14f874decfdd5616b9fb3804154dd2560ebad0a1"
    ],
    "spl": "2025-09-01",
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/14f874decfdd5616b9fb3804154dd2560ebad0a1",
            "target": {
                "function": "showDismissibleKeyguard",
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "53110976986727826745012391277412001162",
                "length": 469.0
            },
            "signature_type": "Function",
            "id": "ASB-A-404252173-7cb6b91c"
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/14f874decfdd5616b9fb3804154dd2560ebad0a1",
            "target": {
                "function": "KeyguardService",
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "319673732979670559273932594517585439603",
                "length": 1235.0
            },
            "signature_type": "Function",
            "id": "ASB-A-404252173-8561bd37"
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/14f874decfdd5616b9fb3804154dd2560ebad0a1",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "299762013212905261322887212060684968711",
                    "2190103179571531646118732716786892301",
                    "10537140773852501480760427689120542655",
                    "215508457842688850767876439392392243095",
                    "273904484769780814852636855735957655305",
                    "198904980846135239138008202747651082760",
                    "131549019979372352019073056993524637149",
                    "299038505897963556330320920719571674613",
                    "171090511766624527407214502187956764901",
                    "120174323833532896976944042787342744943",
                    "252266292509362318653387765667842328546",
                    "108420304567526705932591944887557447711",
                    "22507195533739256989426653925545736023",
                    "175129239960513559978030496938510201289",
                    "59643440053343347558642716143813228323",
                    "266467421320682859761296962874588168303",
                    "114763453852314145694939385375158225766"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-404252173-f35fcc83"
        }
    ],
    "types": [
        "EoP"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-404252173.json"

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15:0
Fixed
15:2025-09-01

Affected versions

Other
15

Ecosystem specific

{
    "severity": "High",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/1de2b4bc46b790bd415cf0d09e17af766382db83"
    ],
    "spl": "2025-09-01",
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/1de2b4bc46b790bd415cf0d09e17af766382db83",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "67463914258819881945036457889354861897",
                    "313162232528710765721358036441381930075",
                    "60741893716015284408742493138543983060",
                    "223954356135584472322304142492918315338",
                    "188088051636725881587366746998127718408",
                    "152687359640194369127572195210192741057",
                    "294134430072931070783241566105918495466",
                    "327350491587318439954200447247129110486",
                    "75323225607535387655798458110284671492",
                    "76476322412690229110274796919526277633",
                    "163017639620719605693164298867149258369",
                    "224879454754417578960454354212612459393",
                    "22507195533739256989426653925545736023",
                    "59961919104088190861660269655859843094",
                    "100099234157792401984734694015238810214",
                    "153378952447524765849198707575339650078"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-404252173-7c4f55ca"
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/1de2b4bc46b790bd415cf0d09e17af766382db83",
            "target": {
                "function": "KeyguardService",
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "99788198260370255432130355245670274726",
                "length": 842.0
            },
            "signature_type": "Function",
            "id": "ASB-A-404252173-85a6e95c"
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/1de2b4bc46b790bd415cf0d09e17af766382db83",
            "target": {
                "function": "showDismissibleKeyguard",
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "101160497034016159186143360875995385371",
                "length": 373.0
            },
            "signature_type": "Function",
            "id": "ASB-A-404252173-a39fd387"
        }
    ],
    "types": [
        "EoP"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-404252173.json"

Android / platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16:0
Fixed
16:2025-09-01

Affected versions

Other
16

Ecosystem specific

{
    "severity": "High",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/71cb04bbbe0c6c9a07ad4f11fff1253fa480cbdc"
    ],
    "spl": "2025-09-01",
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/71cb04bbbe0c6c9a07ad4f11fff1253fa480cbdc",
            "target": {
                "function": "showDismissibleKeyguard",
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "110523820707884031120745551694318071263",
                "length": 593.0
            },
            "signature_type": "Function",
            "id": "ASB-A-404252173-19153a7e"
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/71cb04bbbe0c6c9a07ad4f11fff1253fa480cbdc",
            "target": {
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "328705736549937340018465320626372623490",
                    "2498621061006664823077301845240727374",
                    "10537140773852501480760427689120542655",
                    "215508457842688850767876439392392243095",
                    "273904484769780814852636855735957655305",
                    "198904980846135239138008202747651082760",
                    "131549019979372352019073056993524637149",
                    "299038505897963556330320920719571674613",
                    "171090511766624527407214502187956764901",
                    "120174323833532896976944042787342744943",
                    "252266292509362318653387765667842328546",
                    "108420304567526705932591944887557447711",
                    "22507195533739256989426653925545736023",
                    "292114082995795596172871128308698869466",
                    "234121922515277664258585958316132089912",
                    "257657618865946147205540833728478584068"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "id": "ASB-A-404252173-2bd4d17c"
        },
        {
            "signature_version": "v1",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/71cb04bbbe0c6c9a07ad4f11fff1253fa480cbdc",
            "target": {
                "function": "KeyguardService",
                "file": "packages/SystemUI/src/com/android/systemui/keyguard/KeyguardService.java"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "319673732979670559273932594517585439603",
                "length": 1235.0
            },
            "signature_type": "Function",
            "id": "ASB-A-404252173-6013d74e"
        }
    ],
    "types": [
        "EoP"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-404252173.json"