In createIntentsList of PackageParser.java , there is a possible way to bypass lazy bundle hardening, allowing modified data to be passed to the next process due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 585.0, "function_hash": "25686159493623211619787215512398345538" }, "id": "ASB-A-373467684-0f294854", "source": "https://android.googlesource.com/platform/frameworks/base/+/65c1a90bf4af54f555ded29ec2384072b1c962b8", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/content/pm/PackageParser.java", "function": "createIntentsList" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "109803237766122648025674423814563045897", "230092335716608527425692838741407045547", "233404416498654765875498009191951814135", "93002042245188852370503082178180262737" ] }, "id": "ASB-A-373467684-24383d32", "source": "https://android.googlesource.com/platform/frameworks/base/+/65c1a90bf4af54f555ded29ec2384072b1c962b8", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/content/pm/PackageParser.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/65c1a90bf4af54f555ded29ec2384072b1c962b8" ], "spl": "2025-06-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 585.0, "function_hash": "25686159493623211619787215512398345538" }, "id": "ASB-A-373467684-5b32fdd8", "source": "https://android.googlesource.com/platform/frameworks/base/+/cfd0ded301a5848b9b2caedb44878ae6ff0a7456", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/content/pm/PackageParser.java", "function": "createIntentsList" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "109803237766122648025674423814563045897", "230092335716608527425692838741407045547", "233404416498654765875498009191951814135", "93002042245188852370503082178180262737" ] }, "id": "ASB-A-373467684-d87b3246", "source": "https://android.googlesource.com/platform/frameworks/base/+/cfd0ded301a5848b9b2caedb44878ae6ff0a7456", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/content/pm/PackageParser.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/cfd0ded301a5848b9b2caedb44878ae6ff0a7456" ], "spl": "2025-06-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "109803237766122648025674423814563045897", "230092335716608527425692838741407045547", "233404416498654765875498009191951814135", "93002042245188852370503082178180262737" ] }, "id": "ASB-A-373467684-26754784", "source": "https://android.googlesource.com/platform/frameworks/base/+/249d11226b24f660af50cac7e41b5fed1d0ee19a", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/content/pm/PackageParser.java" }, "signature_type": "Line" }, { "digest": { "length": 585.0, "function_hash": "25686159493623211619787215512398345538" }, "id": "ASB-A-373467684-f4b0b2df", "source": "https://android.googlesource.com/platform/frameworks/base/+/249d11226b24f660af50cac7e41b5fed1d0ee19a", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/content/pm/PackageParser.java", "function": "createIntentsList" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/249d11226b24f660af50cac7e41b5fed1d0ee19a" ], "spl": "2025-06-01", "severity": "High", "types": [ "EoP" ] }
{ "vanir_signatures": [ { "digest": { "length": 585.0, "function_hash": "25686159493623211619787215512398345538" }, "id": "ASB-A-373467684-3712c895", "source": "https://android.googlesource.com/platform/frameworks/base/+/9937e7194ae9a2051c90d38a5bd7e7505b19cb87", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/content/pm/PackageParser.java", "function": "createIntentsList" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "109803237766122648025674423814563045897", "230092335716608527425692838741407045547", "233404416498654765875498009191951814135", "93002042245188852370503082178180262737" ] }, "id": "ASB-A-373467684-dd64bd42", "source": "https://android.googlesource.com/platform/frameworks/base/+/9937e7194ae9a2051c90d38a5bd7e7505b19cb87", "deprecated": false, "signature_version": "v1", "target": { "file": "core/java/android/content/pm/PackageParser.java" }, "signature_type": "Line" } ], "fixes": [ "https://android.googlesource.com/platform/frameworks/base/+/9937e7194ae9a2051c90d38a5bd7e7505b19cb87" ], "spl": "2025-06-01", "severity": "High", "types": [ "EoP" ] }