1412cbcc0c10 : Fix silence-injection policy skip in VirtualAudioController
f064617cb9cc : [26Q2] Mitigate BAL bypass via Companion Device Manager
c715c992cad0 : Fix boot-loop vulnerability in setPermissionGrantState
ec56593e44df : Fix a regression in ECM mode setting after package install
27be977cd805 : Sanitize labels in GrantCredentialsPermissionActivity
28830f292a06 : aapt2: Sanitize Javadoc comments to prevent code injection
724976bd27bd : Fix potential NPEs in PduParser.parsePartHeaders
1c37e9ef69ea : RESTRICT AUTOMERGE: Fix vulnerabilities in PduParser
7e42d365a0c2 : ResStringPool: Validate styleCount and offsets
9644b7e34bb0 : Truncate long device admin descriptions
bbf84d307ba6 : Limit knownActivityEmbeddingCerts in manifest
c54a3ee92fa2 : Use byte count rather than string length for NMS component name check
1f47cb234369 : SystemUi UsbDialog: fix label vulnerability
45c98d340469 : Fix path traversal and missing ownership check in LocaleManagerService
9277b3da7bea : Add Task-level input sink to block cross-task tap pass-through
64cbb2d0021d : Move input sink on top of the Activity when needed
865939513d46 : Check notification permission in getAuthToken(notifyOnAuthFailure).
560b2df86acf : Add size validation and trimming for ShortcutInfo objects.
cbb9f1f1ab9c : Remove CLASS_EXISTENCE_CHECK metadata from ConnectivityCallListenerService
43ef4a09e448 : RESTRICT AUTOMERGE Fix security vulnerability in getManageSpaceActivityIntent
03988cf95e56 : Validate caller UID in openProxyFileDescriptor
5a73367d5b3a : Add bracket checking support to SQLiteTokenizer
8800ef252b9f : [LocalImageResolver] Fix security check bypass
dc8814dec422 : Hide media on smartspace view when setting is disabled
3df35f926c78 : Update host visibility whenever lockscreen state changes
4d1f600cbcbb : Autofill SaveUi URL validation and FLAG_IMMUTABLE
7d46aaa9199b : [AppWidget] Strip URI grants in ConfigActivityProxy
b8e217c4e6cd : Fix BAL bypass via getAppMarketActivityIntent
6acdd7f1a72d : LauncherApps: Scrub sensitive URIs in install sessions
b78e05338801 : Remove usage of Parcel.allowSquashing in RemoteViews and immediate unparceling of Bundle
56f83ee5f1f5 : Revert^2 "Writing ApplicationInfoCache instead of multiple ApplicationInfos for nested RemoteViews"
236258a3e304 : Fix using the base type for checking
31e7981c9d23 : Properly parse meta_key in AccountsDb.
79dd06a8c17c : CVE-2025-22442: set profile user restrictions earlier
4c5500a0d604 : Don't parse 3p recognizer metadata in safe mode
89e9c4b37577 : Dedup SessionParams.whitelistedRestrictedPermissions
250af57de977 : RESTRICT AUTOMERGE Filter ignorable Unicode codepoints in ExternalStorageProvider
323c8b968a88 : Fix & speed up IntentForwarderActivityTest
7e25b93a1faa : Validate caller in SlicePermissionActivity to prevent spoofing.
3cc466bb712c : RESTRICT AUTOMERGE [ExternalStorageProvider] Revoke URI permissions by path
5cf100905634 : Restrict VirtualDeviceImpl methods to device owner.
8df772fb59b4 : Update URI permission granting logic in Intent Redirection Hardening
a2f24fcecabd : Move intent redirect checks before intent resolution.
ee7ea482d39e : Fix intent redirect bypass via selector in addCreatorToken
110da4cfe2a8 : [PackageInstaller] fix an inverted boolean check
743a34f05af0 : Refactor: Add permission checks to Unarchive activities
6f8d24ddbe71 : Set min_sdk_version in GooglePackageInstaller
a00072f03623 : Block adding toast windows to non-empty tokens.
4b3bf7fb29ec : [ClipboardService] Check notification setting for given user
a44880c82aac : Use consistent mmap/unmap sizes in MemoryIntArray