In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"types": [
"ID"
],
"vanir_signatures": [
{
"id": "ASB-A-309407957-21a5757e",
"digest": {
"length": 539.0,
"function_hash": "254295238308086076035495037435727539914"
},
"signature_type": "Function",
"target": {
"file": "libs/androidfw/CursorWindow.cpp",
"function": "CursorWindow::create"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823"
},
{
"id": "ASB-A-309407957-e5a135d2",
"digest": {
"line_hashes": [
"26873316175401722726514673650709571911",
"300215652726136324139284894927596639103",
"47606514160011987552360396234732153973",
"167876416654811209050624263343396057121"
],
"threshold": 0.9
},
"signature_type": "Line",
"target": {
"file": "libs/androidfw/CursorWindow.cpp"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823"
}
],
"spl": "2025-06-01",
"severity": "High",
"fixes": [
"https://googleplex-android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823"
]
}
{
"types": [
"ID"
],
"vanir_signatures": [
{
"id": "ASB-A-309407957-10158c9d",
"digest": {
"line_hashes": [
"26873316175401722726514673650709571911",
"300215652726136324139284894927596639103",
"47606514160011987552360396234732153973",
"167876416654811209050624263343396057121"
],
"threshold": 0.9
},
"signature_type": "Line",
"target": {
"file": "libs/androidfw/CursorWindow.cpp"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef"
},
{
"id": "ASB-A-309407957-1cac09cf",
"digest": {
"length": 539.0,
"function_hash": "254295238308086076035495037435727539914"
},
"signature_type": "Function",
"target": {
"file": "libs/androidfw/CursorWindow.cpp",
"function": "CursorWindow::create"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef"
}
],
"spl": "2025-06-01",
"severity": "High",
"fixes": [
"https://googleplex-android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef"
]
}
{
"types": [
"ID"
],
"vanir_signatures": [
{
"id": "ASB-A-309407957-4361cfde",
"digest": {
"length": 539.0,
"function_hash": "254295238308086076035495037435727539914"
},
"signature_type": "Function",
"target": {
"file": "libs/androidfw/CursorWindow.cpp",
"function": "CursorWindow::create"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958"
},
{
"id": "ASB-A-309407957-ed2703fc",
"digest": {
"line_hashes": [
"26873316175401722726514673650709571911",
"300215652726136324139284894927596639103",
"47606514160011987552360396234732153973",
"167876416654811209050624263343396057121"
],
"threshold": 0.9
},
"signature_type": "Line",
"target": {
"file": "libs/androidfw/CursorWindow.cpp"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958"
}
],
"spl": "2025-06-01",
"severity": "High",
"fixes": [
"https://googleplex-android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958"
]
}
{
"types": [
"ID"
],
"vanir_signatures": [
{
"id": "ASB-A-309407957-df957ada",
"digest": {
"line_hashes": [
"26873316175401722726514673650709571911",
"300215652726136324139284894927596639103",
"47606514160011987552360396234732153973",
"167876416654811209050624263343396057121"
],
"threshold": 0.9
},
"signature_type": "Line",
"target": {
"file": "libs/androidfw/CursorWindow.cpp"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613"
},
{
"id": "ASB-A-309407957-e80897c8",
"digest": {
"length": 539.0,
"function_hash": "254295238308086076035495037435727539914"
},
"signature_type": "Function",
"target": {
"file": "libs/androidfw/CursorWindow.cpp",
"function": "CursorWindow::create"
},
"deprecated": false,
"signature_version": "v1",
"source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613"
}
],
"spl": "2025-06-01",
"severity": "High",
"fixes": [
"https://googleplex-android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613"
]
}