In writeToParcel of CursorWindow.cpp, there is a possible out of bounds read due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "severity": "High", "types": [ "ID" ], "vanir_signatures": [ { "target": { "function": "CursorWindow::create", "file": "libs/androidfw/CursorWindow.cpp" }, "signature_type": "Function", "source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823", "signature_version": "v1", "deprecated": false, "digest": { "length": 539.0, "function_hash": "254295238308086076035495037435727539914" }, "id": "ASB-A-309407957-21a5757e" }, { "target": { "file": "libs/androidfw/CursorWindow.cpp" }, "signature_type": "Line", "source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823", "signature_version": "v1", "deprecated": false, "digest": { "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ], "threshold": 0.9 }, "id": "ASB-A-309407957-e5a135d2" } ], "spl": "2025-06-01", "fixes": [ "https://googleplex-android.googlesource.com/platform/frameworks/base/+/9dc64621d896d05fcb0e6f45792a307fde130823" ] }
{ "severity": "High", "types": [ "ID" ], "vanir_signatures": [ { "target": { "file": "libs/androidfw/CursorWindow.cpp" }, "signature_type": "Line", "source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef", "signature_version": "v1", "deprecated": false, "digest": { "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ], "threshold": 0.9 }, "id": "ASB-A-309407957-10158c9d" }, { "target": { "function": "CursorWindow::create", "file": "libs/androidfw/CursorWindow.cpp" }, "signature_type": "Function", "source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef", "signature_version": "v1", "deprecated": false, "digest": { "length": 539.0, "function_hash": "254295238308086076035495037435727539914" }, "id": "ASB-A-309407957-1cac09cf" } ], "spl": "2025-06-01", "fixes": [ "https://googleplex-android.googlesource.com/platform/frameworks/base/+/ae4b644a7cfb66f1e51ade508f115aec63bc16ef" ] }
{ "severity": "High", "types": [ "ID" ], "vanir_signatures": [ { "target": { "function": "CursorWindow::create", "file": "libs/androidfw/CursorWindow.cpp" }, "signature_type": "Function", "source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958", "signature_version": "v1", "deprecated": false, "digest": { "length": 539.0, "function_hash": "254295238308086076035495037435727539914" }, "id": "ASB-A-309407957-4361cfde" }, { "target": { "file": "libs/androidfw/CursorWindow.cpp" }, "signature_type": "Line", "source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958", "signature_version": "v1", "deprecated": false, "digest": { "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ], "threshold": 0.9 }, "id": "ASB-A-309407957-ed2703fc" } ], "spl": "2025-06-01", "fixes": [ "https://googleplex-android.googlesource.com/platform/frameworks/base/+/5b26a62b4d813b8ccc1de81641e87c9e95c8d958" ] }
{ "severity": "High", "types": [ "ID" ], "vanir_signatures": [ { "target": { "file": "libs/androidfw/CursorWindow.cpp" }, "signature_type": "Line", "source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613", "signature_version": "v1", "deprecated": false, "digest": { "line_hashes": [ "26873316175401722726514673650709571911", "300215652726136324139284894927596639103", "47606514160011987552360396234732153973", "167876416654811209050624263343396057121" ], "threshold": 0.9 }, "id": "ASB-A-309407957-df957ada" }, { "target": { "function": "CursorWindow::create", "file": "libs/androidfw/CursorWindow.cpp" }, "signature_type": "Function", "source": "https://googleplex-android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613", "signature_version": "v1", "deprecated": false, "digest": { "length": 539.0, "function_hash": "254295238308086076035495037435727539914" }, "id": "ASB-A-309407957-e80897c8" } ], "spl": "2025-06-01", "fixes": [ "https://googleplex-android.googlesource.com/platform/frameworks/base/+/c07e0eba29ee1f92b4d540f07a05b8e306601613" ] }