In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"types": [
"EoP"
],
"vanir_signatures": [
{
"signature_type": "Function",
"source": "https://android.googlesource.com/platform/frameworks/base/+/50d18b36c708a7332eedecd88bc5e2cb2323b958",
"deprecated": false,
"digest": {
"length": 10802.0,
"function_hash": "307169313865062868325471251248423105055"
},
"signature_version": "v1",
"target": {
"function": "LoadedPackage::Load",
"file": "libs/androidfw/LoadedArsc.cpp"
},
"id": "ASB-A-484973621-35e873f6"
},
{
"signature_type": "Line",
"id": "ASB-A-484973621-ec369263",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/50d18b36c708a7332eedecd88bc5e2cb2323b958",
"signature_version": "v1",
"target": {
"file": "libs/androidfw/LoadedArsc.cpp"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"78350818810666849271249345144475063362",
"61361269054877775450248921911125581146",
"221851187440703759003140805735154998061",
"200087880818464197053450652257171203066"
]
}
}
],
"severity": "High",
"spl": "2026-06-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/50d18b36c708a7332eedecd88bc5e2cb2323b958"
]
}{
"types": [
"EoP"
],
"vanir_signatures": [
{
"signature_type": "Line",
"id": "ASB-A-484973621-40b87790",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"78350818810666849271249345144475063362",
"61361269054877775450248921911125581146",
"221851187440703759003140805735154998061",
"200087880818464197053450652257171203066"
]
},
"signature_version": "v1",
"target": {
"file": "libs/androidfw/LoadedArsc.cpp"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/93ca69c4f9bbb24947dc66ca004284749a1e8368"
},
{
"signature_type": "Function",
"id": "ASB-A-484973621-c1bf31d9",
"deprecated": false,
"digest": {
"length": 10243.0,
"function_hash": "104734282722271832316981151854006945191"
},
"signature_version": "v1",
"target": {
"function": "LoadedPackage::Load",
"file": "libs/androidfw/LoadedArsc.cpp"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/93ca69c4f9bbb24947dc66ca004284749a1e8368"
}
],
"severity": "High",
"spl": "2026-06-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/93ca69c4f9bbb24947dc66ca004284749a1e8368"
]
}{
"types": [
"EoP"
],
"vanir_signatures": [
{
"signature_type": "Function",
"id": "ASB-A-484973621-9e10ca9b",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/1a2ac7001bbbfbc1906429d4d404b1ab651cdc7e",
"signature_version": "v1",
"target": {
"function": "LoadedPackage::Load",
"file": "libs/androidfw/LoadedArsc.cpp"
},
"digest": {
"length": 10243.0,
"function_hash": "104734282722271832316981151854006945191"
}
},
{
"signature_type": "Line",
"id": "ASB-A-484973621-9f69521d",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/1a2ac7001bbbfbc1906429d4d404b1ab651cdc7e",
"signature_version": "v1",
"target": {
"file": "libs/androidfw/LoadedArsc.cpp"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"78350818810666849271249345144475063362",
"61361269054877775450248921911125581146",
"221851187440703759003140805735154998061",
"200087880818464197053450652257171203066"
]
}
}
],
"severity": "High",
"spl": "2026-06-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/1a2ac7001bbbfbc1906429d4d404b1ab651cdc7e"
]
}{
"types": [
"EoP"
],
"vanir_signatures": [
{
"signature_type": "Line",
"id": "ASB-A-484973621-377ef0cc",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"78350818810666849271249345144475063362",
"61361269054877775450248921911125581146",
"221851187440703759003140805735154998061",
"200087880818464197053450652257171203066"
]
},
"signature_version": "v1",
"target": {
"file": "libs/androidfw/LoadedArsc.cpp"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/a3658d71a7700006019f16bca63cfd3c6c03462d"
},
{
"signature_type": "Function",
"id": "ASB-A-484973621-8538f8f6",
"deprecated": false,
"source": "https://android.googlesource.com/platform/frameworks/base/+/a3658d71a7700006019f16bca63cfd3c6c03462d",
"signature_version": "v1",
"target": {
"file": "libs/androidfw/LoadedArsc.cpp",
"function": "LoadedPackage::Load"
},
"digest": {
"length": 10243.0,
"function_hash": "104734282722271832316981151854006945191"
}
}
],
"severity": "High",
"spl": "2026-06-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/a3658d71a7700006019f16bca63cfd3c6c03462d"
]
}{
"types": [
"EoP"
],
"vanir_signatures": [
{
"signature_type": "Function",
"id": "ASB-A-484973621-16b59f6e",
"digest": {
"length": 10066.0,
"function_hash": "60998659444498194944723808679219033274"
},
"source": "https://android.googlesource.com/platform/frameworks/base/+/ce1e718d216d256e3f147160da05d291227b8807",
"signature_version": "v1",
"target": {
"function": "LoadedPackage::Load",
"file": "libs/androidfw/LoadedArsc.cpp"
},
"deprecated": false
},
{
"signature_type": "Line",
"source": "https://android.googlesource.com/platform/frameworks/base/+/ce1e718d216d256e3f147160da05d291227b8807",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"78350818810666849271249345144475063362",
"61361269054877775450248921911125581146",
"221851187440703759003140805735154998061",
"200087880818464197053450652257171203066"
]
},
"signature_version": "v1",
"target": {
"file": "libs/androidfw/LoadedArsc.cpp"
},
"id": "ASB-A-484973621-76ddbd01"
}
],
"severity": "High",
"spl": "2026-06-01",
"fixes": [
"https://android.googlesource.com/platform/frameworks/base/+/ce1e718d216d256e3f147160da05d291227b8807"
]
}