ASB-A-404254549

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-404254549.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-404254549
Aliases
  • A-404254549
  • CVE-2025-48618
Published
2025-12-01T00:00:00Z
Modified
2025-12-11T16:45:11.149671Z
Summary
[none]
Details

In processLaunchBrowser of CommandParamsFactory.java, there is a possible browser interaction from the lockscreen due to improper locking. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android

platform/frameworks/opt/telephony

Package

Name
platform/frameworks/opt/telephony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16-qpr2-next:0
Fixed
16-qpr2-next:2025-12-01

Affected versions

Other

16-qpr2-next

Ecosystem specific

{
    "spl": "2025-12-01",
    "vanir_signatures": [
        {
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/dcf5c112a93dc8fcc67d65434707e205fd79cee2",
            "id": "ASB-A-404254549-0d3740be",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "126841584836587469014955577698167293997",
                    "168254648683542555738692921111058362169",
                    "93597993831312728335032933858035332714",
                    "201576147938869780718846071442591858311",
                    "296332964556440632912533357557336683078",
                    "102447935041989546204727891996243023724",
                    "56155387748275661933978624091286924453",
                    "336818962558103374523242084094841889704",
                    "46632421777451632340080436636403098793",
                    "247717101312116447828082806340619679576",
                    "283109049979985087688153187750762351747",
                    "204400155171772489866802819424636014856",
                    "180631327578771327964947079217621243298",
                    "255581152413201755700612624712317165337"
                ]
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/dcf5c112a93dc8fcc67d65434707e205fd79cee2",
            "id": "ASB-A-404254549-14f747d5",
            "digest": {
                "function_hash": "40406192771755523414762501391771993671",
                "length": 465.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/ResultException.java",
                "function": "ResultException"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/dcf5c112a93dc8fcc67d65434707e205fd79cee2",
            "id": "ASB-A-404254549-162288c5",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "117668481257297107530764335499844443242",
                    "327268473740061505278911752601663297328",
                    "300373037912090030938662428104802295310",
                    "177996292300046045383743207326557855174",
                    "23056403281171326616536705075062193914",
                    "247143444613494069882996688514518247832",
                    "65775505213269645513353343758759787473"
                ]
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/ResultException.java"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/dcf5c112a93dc8fcc67d65434707e205fd79cee2",
            "id": "ASB-A-404254549-4ef6c021",
            "digest": {
                "function_hash": "283287314837110726171987907853411129386",
                "length": 519.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java",
                "function": "CommandParamsFactory"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/dcf5c112a93dc8fcc67d65434707e205fd79cee2",
            "id": "ASB-A-404254549-8d32e9ff",
            "digest": {
                "function_hash": "245255220764803643324960432761250446283",
                "length": 1345.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java",
                "function": "processLaunchBrowser"
            },
            "deprecated": false,
            "signature_version": "v1"
        }
    ],
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/opt/telephony/+/dcf5c112a93dc8fcc67d65434707e205fd79cee2"
    ],
    "severity": "High"
}

platform/frameworks/opt/telephony

Package

Name
platform/frameworks/opt/telephony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15:0
Fixed
15:2025-12-01

Affected versions

Other

15

Ecosystem specific

{
    "spl": "2025-12-01",
    "vanir_signatures": [
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/928df99dd7389e24e953101766b0810e7e526555",
            "id": "ASB-A-404254549-0b916b4e",
            "digest": {
                "function_hash": "283287314837110726171987907853411129386",
                "length": 519.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java",
                "function": "CommandParamsFactory"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/928df99dd7389e24e953101766b0810e7e526555",
            "id": "ASB-A-404254549-1fe05b01",
            "digest": {
                "function_hash": "40406192771755523414762501391771993671",
                "length": 465.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/ResultException.java",
                "function": "ResultException"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/928df99dd7389e24e953101766b0810e7e526555",
            "id": "ASB-A-404254549-88c74f6f",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "192332858909354083000301575240343213579",
                    "168254648683542555738692921111058362169",
                    "93597993831312728335032933858035332714",
                    "201576147938869780718846071442591858311",
                    "296332964556440632912533357557336683078",
                    "102447935041989546204727891996243023724",
                    "56155387748275661933978624091286924453",
                    "336818962558103374523242084094841889704",
                    "46632421777451632340080436636403098793",
                    "247717101312116447828082806340619679576",
                    "283109049979985087688153187750762351747",
                    "204400155171772489866802819424636014856",
                    "180631327578771327964947079217621243298",
                    "255581152413201755700612624712317165337"
                ]
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/928df99dd7389e24e953101766b0810e7e526555",
            "id": "ASB-A-404254549-91f59a45",
            "digest": {
                "function_hash": "245255220764803643324960432761250446283",
                "length": 1345.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java",
                "function": "processLaunchBrowser"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/928df99dd7389e24e953101766b0810e7e526555",
            "id": "ASB-A-404254549-ec96ef30",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "117668481257297107530764335499844443242",
                    "327268473740061505278911752601663297328",
                    "300373037912090030938662428104802295310",
                    "177996292300046045383743207326557855174",
                    "23056403281171326616536705075062193914",
                    "247143444613494069882996688514518247832",
                    "65775505213269645513353343758759787473"
                ]
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/ResultException.java"
            },
            "deprecated": false,
            "signature_version": "v1"
        }
    ],
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/opt/telephony/+/928df99dd7389e24e953101766b0810e7e526555"
    ],
    "severity": "High"
}

platform/frameworks/opt/telephony

Package

Name
platform/frameworks/opt/telephony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16:0
Fixed
16:2025-12-01

Affected versions

Other

16

Ecosystem specific

{
    "spl": "2025-12-01",
    "vanir_signatures": [
        {
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/d3774ac65a38121b242f75388a08971883cc05d2",
            "id": "ASB-A-404254549-0dbb476c",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "117668481257297107530764335499844443242",
                    "327268473740061505278911752601663297328",
                    "300373037912090030938662428104802295310",
                    "177996292300046045383743207326557855174",
                    "23056403281171326616536705075062193914",
                    "247143444613494069882996688514518247832",
                    "65775505213269645513353343758759787473"
                ]
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/ResultException.java"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/d3774ac65a38121b242f75388a08971883cc05d2",
            "id": "ASB-A-404254549-2b038a87",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "192332858909354083000301575240343213579",
                    "168254648683542555738692921111058362169",
                    "93597993831312728335032933858035332714",
                    "201576147938869780718846071442591858311",
                    "296332964556440632912533357557336683078",
                    "102447935041989546204727891996243023724",
                    "56155387748275661933978624091286924453",
                    "336818962558103374523242084094841889704",
                    "46632421777451632340080436636403098793",
                    "247717101312116447828082806340619679576",
                    "283109049979985087688153187750762351747",
                    "204400155171772489866802819424636014856",
                    "180631327578771327964947079217621243298",
                    "255581152413201755700612624712317165337"
                ]
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/d3774ac65a38121b242f75388a08971883cc05d2",
            "id": "ASB-A-404254549-4aa23628",
            "digest": {
                "function_hash": "40406192771755523414762501391771993671",
                "length": 465.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/ResultException.java",
                "function": "ResultException"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/d3774ac65a38121b242f75388a08971883cc05d2",
            "id": "ASB-A-404254549-62cc75a9",
            "digest": {
                "function_hash": "283287314837110726171987907853411129386",
                "length": 519.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java",
                "function": "CommandParamsFactory"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/d3774ac65a38121b242f75388a08971883cc05d2",
            "id": "ASB-A-404254549-ea060c27",
            "digest": {
                "function_hash": "245255220764803643324960432761250446283",
                "length": 1345.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java",
                "function": "processLaunchBrowser"
            },
            "deprecated": false,
            "signature_version": "v1"
        }
    ],
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/opt/telephony/+/d3774ac65a38121b242f75388a08971883cc05d2"
    ],
    "severity": "High"
}

platform/frameworks/opt/telephony

Package

Name
platform/frameworks/opt/telephony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13:0
Fixed
13:2025-12-01

Affected versions

Other

13

Ecosystem specific

{
    "spl": "2025-12-01",
    "vanir_signatures": [
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/12ae4849fad33bc6b1d145428d8c547a5912199e",
            "id": "ASB-A-404254549-1de1addb",
            "digest": {
                "function_hash": "245255220764803643324960432761250446283",
                "length": 1345.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java",
                "function": "processLaunchBrowser"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/12ae4849fad33bc6b1d145428d8c547a5912199e",
            "id": "ASB-A-404254549-25a174ab",
            "digest": {
                "function_hash": "57267232105146911331819391053436561220",
                "length": 313.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java",
                "function": "CommandParamsFactory"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/12ae4849fad33bc6b1d145428d8c547a5912199e",
            "id": "ASB-A-404254549-6804c41c",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "117668481257297107530764335499844443242",
                    "327268473740061505278911752601663297328",
                    "300373037912090030938662428104802295310",
                    "177996292300046045383743207326557855174",
                    "23056403281171326616536705075062193914",
                    "247143444613494069882996688514518247832",
                    "65775505213269645513353343758759787473"
                ]
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/ResultException.java"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/12ae4849fad33bc6b1d145428d8c547a5912199e",
            "id": "ASB-A-404254549-6e4d3337",
            "digest": {
                "function_hash": "40406192771755523414762501391771993671",
                "length": 465.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/ResultException.java",
                "function": "ResultException"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/12ae4849fad33bc6b1d145428d8c547a5912199e",
            "id": "ASB-A-404254549-eff53b60",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "192332858909354083000301575240343213579",
                    "168254648683542555738692921111058362169",
                    "93597993831312728335032933858035332714",
                    "132661127246613407098264706443338888972",
                    "249290390951984909688795074319993036822",
                    "178787134647457598986328236406502151650",
                    "336818962558103374523242084094841889704",
                    "46632421777451632340080436636403098793",
                    "247717101312116447828082806340619679576",
                    "283109049979985087688153187750762351747",
                    "204400155171772489866802819424636014856",
                    "180631327578771327964947079217621243298",
                    "255581152413201755700612624712317165337"
                ]
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java"
            },
            "deprecated": false,
            "signature_version": "v1"
        }
    ],
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/opt/telephony/+/12ae4849fad33bc6b1d145428d8c547a5912199e"
    ],
    "severity": "High"
}

platform/frameworks/opt/telephony

Package

Name
platform/frameworks/opt/telephony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14:0
Fixed
14:2025-12-01

Affected versions

Other

14

Ecosystem specific

{
    "spl": "2025-12-01",
    "vanir_signatures": [
        {
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/ddafa596ceef0e0866db0a17d49c5fd4470467b8",
            "id": "ASB-A-404254549-4b6506a7",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "192332858909354083000301575240343213579",
                    "168254648683542555738692921111058362169",
                    "93597993831312728335032933858035332714",
                    "187403188051938735880290827081193559597",
                    "47296757770091565774755302790624994189",
                    "182948830206079551311604649551017378172",
                    "336818962558103374523242084094841889704",
                    "46632421777451632340080436636403098793",
                    "247717101312116447828082806340619679576",
                    "283109049979985087688153187750762351747",
                    "204400155171772489866802819424636014856",
                    "180631327578771327964947079217621243298",
                    "255581152413201755700612624712317165337"
                ]
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/ddafa596ceef0e0866db0a17d49c5fd4470467b8",
            "id": "ASB-A-404254549-51dd3548",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "117668481257297107530764335499844443242",
                    "327268473740061505278911752601663297328",
                    "300373037912090030938662428104802295310",
                    "177996292300046045383743207326557855174",
                    "23056403281171326616536705075062193914",
                    "247143444613494069882996688514518247832",
                    "65775505213269645513353343758759787473"
                ]
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/ResultException.java"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/ddafa596ceef0e0866db0a17d49c5fd4470467b8",
            "id": "ASB-A-404254549-5209685d",
            "digest": {
                "function_hash": "40406192771755523414762501391771993671",
                "length": 465.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/ResultException.java",
                "function": "ResultException"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/ddafa596ceef0e0866db0a17d49c5fd4470467b8",
            "id": "ASB-A-404254549-5b6e1254",
            "digest": {
                "function_hash": "245255220764803643324960432761250446283",
                "length": 1345.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java",
                "function": "processLaunchBrowser"
            },
            "deprecated": false,
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/opt/telephony/+/ddafa596ceef0e0866db0a17d49c5fd4470467b8",
            "id": "ASB-A-404254549-e418e3b6",
            "digest": {
                "function_hash": "283287314837110726171987907853411129386",
                "length": 519.0
            },
            "target": {
                "file": "src/java/com/android/internal/telephony/cat/CommandParamsFactory.java",
                "function": "CommandParamsFactory"
            },
            "deprecated": false,
            "signature_version": "v1"
        }
    ],
    "types": [
        "EoP"
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/opt/telephony/+/ddafa596ceef0e0866db0a17d49c5fd4470467b8"
    ],
    "severity": "High"
}