ASB-A-438186009

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-438186009.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-438186009
Aliases
  • A-438186009
  • CVE-2026-0070
Published
2026-06-01T00:00:00Z
Modified
2026-06-23T15:45:40.410020820Z
Summary
[none]
Details

In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android
platform/frameworks/base

Package

Name
platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
17-next:0
Fixed
17-next:2026-06-01

Affected versions

Other
17-next

Ecosystem specific

{
    "spl": "2026-06-01",
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/79cca47a6201c9debdf5695b240926c3f1944166"
    ],
    "types": [
        "DoS"
    ],
    "vanir_signatures": [
        {
            "digest": {
                "length": 1501.0,
                "function_hash": "335149920525558462994404269237638391269"
            },
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/79cca47a6201c9debdf5695b240926c3f1944166",
            "id": "ASB-A-438186009-acb24eb4",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java",
                "function": "setApplicationHidden"
            }
        },
        {
            "digest": {
                "length": 733.0,
                "function_hash": "315259052800142157265435189057750018541"
            },
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/79cca47a6201c9debdf5695b240926c3f1944166",
            "id": "ASB-A-438186009-d7ed781e",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java",
                "function": "dumpResources"
            }
        },
        {
            "signature_version": "v1",
            "id": "ASB-A-438186009-e97ef8d8",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/79cca47a6201c9debdf5695b240926c3f1944166",
            "signature_type": "Line",
            "deprecated": false,
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java"
            },
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "6092387668215313025417762827665573007",
                    "225272786115913257972947217315642282011",
                    "241405310850211474395422482270537390830",
                    "241687692444606202272449932470876959372",
                    "181397407319905064678244527735915627369",
                    "316298545725525957651624668707700307052",
                    "212627851799453202386643072362596635696",
                    "85498568986254432836380442243385848459",
                    "87636560343521544508148697268323663003",
                    "327663528310505349556952355993999590017",
                    "302498248168541542815919668799669381764"
                ]
            }
        }
    ],
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-438186009.json"
platform/frameworks/base

Package

Name
platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15:0
Fixed
15:2026-06-01

Affected versions

Other
15

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/77371d16afb4574acfa78c67bdadb3c08cb53343"
    ],
    "severity": "High",
    "types": [
        "DoS"
    ],
    "spl": "2026-06-01",
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "id": "ASB-A-438186009-47aa773f",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/77371d16afb4574acfa78c67bdadb3c08cb53343",
            "signature_type": "Function",
            "deprecated": false,
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java",
                "function": "setApplicationHidden"
            },
            "digest": {
                "length": 1511.0,
                "function_hash": "62305857649003667543974786968857910844"
            }
        },
        {
            "digest": {
                "length": 733.0,
                "function_hash": "315259052800142157265435189057750018541"
            },
            "id": "ASB-A-438186009-f264896f",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/77371d16afb4574acfa78c67bdadb3c08cb53343",
            "signature_type": "Function",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java",
                "function": "dumpResources"
            }
        },
        {
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java"
            },
            "id": "ASB-A-438186009-fcec9087",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/77371d16afb4574acfa78c67bdadb3c08cb53343",
            "signature_type": "Line",
            "deprecated": false,
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "6092387668215313025417762827665573007",
                    "225272786115913257972947217315642282011",
                    "241405310850211474395422482270537390830",
                    "241687692444606202272449932470876959372",
                    "181397407319905064678244527735915627369",
                    "316298545725525957651624668707700307052",
                    "212627851799453202386643072362596635696",
                    "55525629966146270102222777748570793405",
                    "317638606902821826831464714837897502373",
                    "327663528310505349556952355993999590017",
                    "302498248168541542815919668799669381764"
                ]
            },
            "signature_version": "v1"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-438186009.json"
platform/frameworks/base

Package

Name
platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16:0
Fixed
16:2026-06-01

Affected versions

Other
16

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/b4b10f40dfd9ed6b5f150dc78a9844cfdd6be632"
    ],
    "severity": "High",
    "vanir_signatures": [
        {
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java"
            },
            "id": "ASB-A-438186009-5700be49",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/b4b10f40dfd9ed6b5f150dc78a9844cfdd6be632",
            "signature_type": "Line",
            "deprecated": false,
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "6092387668215313025417762827665573007",
                    "225272786115913257972947217315642282011",
                    "241405310850211474395422482270537390830",
                    "241687692444606202272449932470876959372",
                    "181397407319905064678244527735915627369",
                    "316298545725525957651624668707700307052",
                    "212627851799453202386643072362596635696",
                    "55525629966146270102222777748570793405",
                    "317638606902821826831464714837897502373",
                    "327663528310505349556952355993999590017",
                    "302498248168541542815919668799669381764"
                ]
            },
            "signature_version": "v1"
        },
        {
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java",
                "function": "setApplicationHidden"
            },
            "id": "ASB-A-438186009-f2364311",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/b4b10f40dfd9ed6b5f150dc78a9844cfdd6be632",
            "signature_type": "Function",
            "deprecated": false,
            "digest": {
                "length": 1511.0,
                "function_hash": "62305857649003667543974786968857910844"
            },
            "signature_version": "v1"
        },
        {
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java",
                "function": "dumpResources"
            },
            "id": "ASB-A-438186009-f2f868e2",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/b4b10f40dfd9ed6b5f150dc78a9844cfdd6be632",
            "signature_type": "Function",
            "deprecated": false,
            "digest": {
                "length": 733.0,
                "function_hash": "315259052800142157265435189057750018541"
            },
            "signature_version": "v1"
        }
    ],
    "spl": "2026-06-01",
    "types": [
        "DoS"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-438186009.json"
platform/frameworks/base

Package

Name
platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16-qpr2:0
Fixed
16-qpr2:2026-06-01

Affected versions

Other
16-qpr2

Ecosystem specific

{
    "severity": "High",
    "spl": "2026-06-01",
    "types": [
        "DoS"
    ],
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "id": "ASB-A-438186009-1f69c186",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/3129a29411bc163eb7ec722bc968d8fa4c67f80f",
            "signature_type": "Function",
            "deprecated": false,
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java",
                "function": "setApplicationHidden"
            },
            "digest": {
                "length": 1501.0,
                "function_hash": "335149920525558462994404269237638391269"
            }
        },
        {
            "digest": {
                "length": 733.0,
                "function_hash": "315259052800142157265435189057750018541"
            },
            "id": "ASB-A-438186009-477ba841",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/3129a29411bc163eb7ec722bc968d8fa4c67f80f",
            "signature_type": "Function",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java",
                "function": "dumpResources"
            }
        },
        {
            "signature_version": "v1",
            "id": "ASB-A-438186009-d791803f",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/3129a29411bc163eb7ec722bc968d8fa4c67f80f",
            "signature_type": "Line",
            "deprecated": false,
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java"
            },
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "6092387668215313025417762827665573007",
                    "225272786115913257972947217315642282011",
                    "241405310850211474395422482270537390830",
                    "241687692444606202272449932470876959372",
                    "181397407319905064678244527735915627369",
                    "316298545725525957651624668707700307052",
                    "212627851799453202386643072362596635696",
                    "85498568986254432836380442243385848459",
                    "87636560343521544508148697268323663003",
                    "327663528310505349556952355993999590017",
                    "302498248168541542815919668799669381764"
                ]
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/3129a29411bc163eb7ec722bc968d8fa4c67f80f"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-438186009.json"
platform/frameworks/base

Package

Name
platform/frameworks/base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14:0
Fixed
14:2026-06-01

Affected versions

Other
14

Ecosystem specific

{
    "fixes": [
        "https://android.googlesource.com/platform/frameworks/base/+/4a97f5239d571788ee26d94a54b7e57f23cbb0d4"
    ],
    "severity": "High",
    "types": [
        "DoS"
    ],
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "6092387668215313025417762827665573007",
                    "225272786115913257972947217315642282011",
                    "241405310850211474395422482270537390830",
                    "241687692444606202272449932470876959372",
                    "181397407319905064678244527735915627369",
                    "316298545725525957651624668707700307052",
                    "212627851799453202386643072362596635696",
                    "275285724250142645022066266433608152772",
                    "266128297703753329906982674345792391773",
                    "327663528310505349556952355993999590017",
                    "302498248168541542815919668799669381764"
                ]
            },
            "id": "ASB-A-438186009-04a51e0f",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/4a97f5239d571788ee26d94a54b7e57f23cbb0d4",
            "signature_type": "Line",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java"
            }
        },
        {
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java",
                "function": "dumpResources"
            },
            "id": "ASB-A-438186009-24e182d7",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/4a97f5239d571788ee26d94a54b7e57f23cbb0d4",
            "signature_type": "Function",
            "deprecated": false,
            "digest": {
                "length": 733.0,
                "function_hash": "315259052800142157265435189057750018541"
            },
            "signature_version": "v1"
        },
        {
            "digest": {
                "length": 1965.0,
                "function_hash": "229504221062569578636971357235157563497"
            },
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/frameworks/base/+/4a97f5239d571788ee26d94a54b7e57f23cbb0d4",
            "id": "ASB-A-438186009-56a57eb7",
            "deprecated": false,
            "signature_version": "v1",
            "target": {
                "file": "services/devicepolicy/java/com/android/server/devicepolicy/DevicePolicyManagerService.java",
                "function": "setApplicationHidden"
            }
        }
    ],
    "spl": "2026-06-01"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-438186009.json"