android-17.0.0_r1 to android-security-17.0.0_r1 AOSP changelog

This only includes the Android Open Source Project changes and does not include any changes in any proprietary components included by Google or any hardware manufacturer. The raw log was generated using a modified version of this script written by JBQ and improved by Al Sutton.

Please do not copy this without attribution to this site and JBQ for the original script.

+- Project: platform/art

70be2043e6 : Make the runtime-generated app image read-only

+- Project: platform/bionic

48a7e3362 : Fix bad free when limit exceeded.

+- Project: platform/build

eb894ac0ca : Version bump to CSV1.260518.009 [core/build_id.mk] e9fbc5fb34 : Version bump to CSV1.260518.008 [core/build_id.mk] 89f4fa927a : Version bump to CSV1.260518.007 [core/build_id.mk] 820cda0c13 : Version bump to CSV1.260518.006 [core/build_id.mk] 4c99ae7c14 : Version bump to CSV1.260518.005 [core/build_id.mk] 37066ee000 : Version bump to CSV1.260518.004 [core/build_id.mk] d6ca31755a : Version bump to CSV1.260518.003 [core/build_id.mk] 3d3f52af2c : Version bump to CSV1.260518.002 [core/build_id.mk] d6b4162bde : Version bump to CSV1.260518.001 [core/build_id.mk]

+- Project: platform/development

21dbe0e7b : Fix potential NPEs in PduParser.parsePartHeaders

+- Project: platform/external/exfatprogs

5ec5ede : ANDROID: Fix fsck overflows when handling bad clu_count or vol_length fields. a6faf5d : ANDROID: Add support for building exfat tests.

+- Project: platform/external/freetype

4321c90fc : Fix heap underflow write in ft_smooth_raster_lcd 65f3c6ba2 : * src/sfnt/ttcolr.c (tt_face_colr_blend_layer): Use FT_ALLOC_MULT. 333924d9d : [ttgxvar] Check for overflow in array size computation.

+- Project: platform/external/libcupsfilters

5c0e5bf1 : Fix integer overflows in raster header processing

+- Project: platform/external/libhevc

9aa38f2 : libhevcdec: Fix heap buffer overflow in ihevcd_get_tu_data_size

+- Project: platform/external/libjxl

069d75c4 : Disable unsigned integer overflow sanitizer in libjxl

+- Project: platform/external/libopenapv

7c797fc : [libopenapv] Add dimension validation in dec_frm_prepare

+- Project: platform/external/libpng

7d98050ef : fix(arm): Resolve out-of-bounds read/write in NEON palette expansion

+- Project: platform/external/libppd

6ce8492f : Fix integer overflow and heap OOB write errors

+- Project: platform/external/rust/beto-rust

1c954de : Remove BetterTogether from AOSP.

+- Project: platform/external/wpa_supplicant_8

14398e6a : wpa_supplicant: Fix OOB read in get_eht_op_width ffd3987b : Fix heap OOB write in Robust AV SCS Response handler 3426cb00 : Fix NAN frequency list handling in AIDL interfaces. b8d36c89 : Fix P2P2 PBMA Cookie Heap Overflow and harden wpa_supplicant/hostapd

+- Project: platform/frameworks/av

073ae498a4 : Fix type confusion in mediatuner service f103cdde76 : Fix race conditions in CryptoHal plugin usage 77f8ddbbd6 : Camera: Fix heap OOB read/write in camera mappers db4f7fd08e : DeprecatedCamera3StreamSplitter: Add bounds check for slot index 237289dd22 : Fix MediaBuffer size-inflation off-by-32 bug 526699cba3 : Fix OOB in DynamicsProcessing MBC band processing 1e00537f8f : Fix signed overflow in convertCleanApertureToRect b8080da682 : [media] Fix heap-buffer-overflow in AudioAttributes unmarshalling

+- Project: platform/frameworks/base

1412cbcc0c10 : Fix silence-injection policy skip in VirtualAudioController f064617cb9cc : [26Q2] Mitigate BAL bypass via Companion Device Manager c715c992cad0 : Fix boot-loop vulnerability in setPermissionGrantState ec56593e44df : Fix a regression in ECM mode setting after package install 27be977cd805 : Sanitize labels in GrantCredentialsPermissionActivity 28830f292a06 : aapt2: Sanitize Javadoc comments to prevent code injection 724976bd27bd : Fix potential NPEs in PduParser.parsePartHeaders 1c37e9ef69ea : RESTRICT AUTOMERGE: Fix vulnerabilities in PduParser 7e42d365a0c2 : ResStringPool: Validate styleCount and offsets 9644b7e34bb0 : Truncate long device admin descriptions bbf84d307ba6 : Limit knownActivityEmbeddingCerts in manifest c54a3ee92fa2 : Use byte count rather than string length for NMS component name check 1f47cb234369 : SystemUi UsbDialog: fix label vulnerability 45c98d340469 : Fix path traversal and missing ownership check in LocaleManagerService 9277b3da7bea : Add Task-level input sink to block cross-task tap pass-through 64cbb2d0021d : Move input sink on top of the Activity when needed 865939513d46 : Check notification permission in getAuthToken(notifyOnAuthFailure). 560b2df86acf : Add size validation and trimming for ShortcutInfo objects. cbb9f1f1ab9c : Remove CLASS_EXISTENCE_CHECK metadata from ConnectivityCallListenerService 43ef4a09e448 : RESTRICT AUTOMERGE Fix security vulnerability in getManageSpaceActivityIntent 03988cf95e56 : Validate caller UID in openProxyFileDescriptor 5a73367d5b3a : Add bracket checking support to SQLiteTokenizer 8800ef252b9f : [LocalImageResolver] Fix security check bypass dc8814dec422 : Hide media on smartspace view when setting is disabled 3df35f926c78 : Update host visibility whenever lockscreen state changes 4d1f600cbcbb : Autofill SaveUi URL validation and FLAG_IMMUTABLE 7d46aaa9199b : [AppWidget] Strip URI grants in ConfigActivityProxy b8e217c4e6cd : Fix BAL bypass via getAppMarketActivityIntent 6acdd7f1a72d : LauncherApps: Scrub sensitive URIs in install sessions b78e05338801 : Remove usage of Parcel.allowSquashing in RemoteViews and immediate unparceling of Bundle 56f83ee5f1f5 : Revert^2 "Writing ApplicationInfoCache instead of multiple ApplicationInfos for nested RemoteViews" 236258a3e304 : Fix using the base type for checking 31e7981c9d23 : Properly parse meta_key in AccountsDb. 79dd06a8c17c : CVE-2025-22442: set profile user restrictions earlier 4c5500a0d604 : Don't parse 3p recognizer metadata in safe mode 89e9c4b37577 : Dedup SessionParams.whitelistedRestrictedPermissions 250af57de977 : RESTRICT AUTOMERGE Filter ignorable Unicode codepoints in ExternalStorageProvider 323c8b968a88 : Fix & speed up IntentForwarderActivityTest 7e25b93a1faa : Validate caller in SlicePermissionActivity to prevent spoofing. 3cc466bb712c : RESTRICT AUTOMERGE [ExternalStorageProvider] Revoke URI permissions by path 5cf100905634 : Restrict VirtualDeviceImpl methods to device owner. 8df772fb59b4 : Update URI permission granting logic in Intent Redirection Hardening a2f24fcecabd : Move intent redirect checks before intent resolution. ee7ea482d39e : Fix intent redirect bypass via selector in addCreatorToken 110da4cfe2a8 : [PackageInstaller] fix an inverted boolean check 743a34f05af0 : Refactor: Add permission checks to Unarchive activities 6f8d24ddbe71 : Set min_sdk_version in GooglePackageInstaller a00072f03623 : Block adding toast windows to non-empty tokens. 4b3bf7fb29ec : [ClipboardService] Check notification setting for given user a44880c82aac : Use consistent mmap/unmap sizes in MemoryIntArray

+- Project: platform/frameworks/opt/telephony

e73ac64878 : Fix ArrayIndexOutOfBoundsException in SIMRecords due to invalid EF_CFIS/EF_CFF 802f8f5c99 : Block in-call MMI execution for USSD requests.

+- Project: platform/hardware/interfaces

d9f6b94ba0 : AIDL CAS HAL: Fix incorrect mmap failure check

+- Project: platform/hardware/nxp/nfc

e245c4b : Fix Use-After-Free in NXP NFC HAL timer teardown

+- Project: platform/hardware/nxp/secure_element

addc064 : Fix out-of-bounds write in SecureElement openLogicalChannel

+- Project: platform/hardware/st/nfc

8a18f33 : Fix out-of-bounds write in stpropnci_process_std bbb2d21 : Fix out-of-bounds write in stpropnci_process

+- Project: platform/packages/apps/Car/Settings

64214ba74 : Replace DeviceAdminInfo.loadDescription() with loadDescriptionSafe() a64ee7401 : Check getLaunchedFromPackage for CE Storage

+- Project: platform/packages/apps/ContactsPicker

824770d : Change to startActivityAsCaller when forwarding ACTION_PICK intent f44519d : Disable System Overlays to prevent tapjack attack

+- Project: platform/packages/apps/Settings

36a70818e79 : Replace DeviceAdminInfo.loadDescription() with loadDescriptionSafe() 759e75cec1c : Sanitize sensitive BiometricsSettingsBase extra a0870b60ba8 : Fix confused deputy in Bluetooth settings dashboard 12fb76cd702 : Sanitize package labels in SettingsApplication 642944e4c4e : Ensure remote device credential alias is used for action CONFIRM_REMOTE_DEVICE_CREDENTIAL. d800aed5a84 : Remove EXTRA_DATA from ConfirmDeviceCredentialActivity a3cbe8fbf28 : [Settings] Strip URI grant flags in AppRestrictionsFragment d1db7e8d999 : Remove dialog building logic from PaymentDefaultDialog onCreate.

+- Project: platform/packages/apps/TV

25c98c91 : [LiveTv] Fix Intent redirection issue in SetupPassthroughActivity 724154d5 : [LiveTV] Specify intent package for "Send Feedback" a10682aa : [LiveTv] Avoid Intent Redirection to permission protected Activities

+- Project: platform/packages/apps/TvSettings

c63a1f6ec : Use loadDescriptionSafe for DeviceAdmin descriptions.

+- Project: platform/packages/modules/Bluetooth

5f719e21ee : Fix buffer overflow in UUID parsing aa513b35ec : GATT: Fix notifications sent to remote device without security checks 62418c92b1 : Fix out-of-bounds heap write in SnoopLogger 01cb44f098 : Fix cross-thread UAF in AvrcpService updates 1af205db6a : Fix uninitialized pointer dereference in MsftExtensionManager 4a9e8875e2 : [RESTRICT AUTOMERGE] Fix SDP server heap buffer overflow d2c0b10836 : [RESTRICT AUTOMERGE] Enforce incoming CTKD security requirements 3b78dbef3e : [RESTRICT AUTOMERGE] Fix heap buffer overflow in A2DP Opus decoder 746c2f474f : Remove btsec_sdp_database_thread_sync flag and old synchronization. 5819c807e8 : Treat encrypted non-SC link as downgrade if SC was previously supported. 1b0d684402 : Unflag remove_bond_caller_info

+- Project: platform/packages/modules/Connectivity

33f9aaedc8 : Rehome enable_d2d_connectivity_service Flag.

+- Project: platform/packages/modules/Nfc

52c0818d3 : Fix integer underflow and OOB access in libnfc-nci f8325e216 : Fix integer underflow in rw_ci_data_cback 8181cc81e : Fix out-of-bounds write in checkUiccListenConfigNeeded 897466771 : Fix out-of-bounds write in NFC activation handling f5089c4c9 : Fix heap buffer overflow in nfa_t4tnfcee_store_rx_buf 19fc32913 : Fix OOB write in rw_mfc_handle_read_op 442e948e4 : Fix potential integer overflow in Type 3 Tag block operations. 0dc8fad01 : Fix bounds check underflow and GKI buffer leak in T4T write 79b153345 : Prevent buffer overflow on oversized HAL packets ebcfc2564 : Fix Heap OOBW in nfa_t4tnfcee_store_rx_buf() 2ad8845ad : Prevent information disclosure over RF in rw_t5t.cc e55c93242 : Fix uint16 loop counter wrap in T3T NDEF CHECK/UPDATE 9f4efdd67 : Terminate MFC NDEF read on length inflation attempt

+- Project: platform/packages/modules/Telephony

e04c40c : Fix server-triggered StackOverflowError in TS.43 phone number fetch

+- Project: platform/packages/modules/Uwb

3be00374c : Enforce ranging permission for OOB ranging APIs. 5dbf65f08 : [GRAPI] Mask Mac Address in BleRangingCapabilities

+- Project: platform/packages/modules/Wifi

78ed579157 : Deny system app status for Private Compute Core UIDs in WifiPermissionsUtil. 9b1148745f : Fix persistent DoS in WifiNetworkSuggestionsManager via PersistableBundle depth bomb

+- Project: platform/packages/modules/adb

12700491 : [adb] Fix Use-After-Free in TLS handshake. fdbd8a5f : [adb] Document and harden async transport flow.

+- Project: platform/packages/providers/ContactsProvider

8b1ebf91 : Restrict max size for Note.NOTE field 5ec4850f : Prevent SQL injection in SelectionBuilder

+- Project: platform/packages/providers/DownloadProvider

adbfd901 : RESTRICT AUTOMERGE Fix ZWSP path bypass in DownloadProvider 30a6a122 : RESTRICT AUTOMERGE Fix DownloadProvider completed download security bypass 6ed0eac9 : RESTRICT AUTOMERGE Fix path traversal vulnerability in DownloadStorageProvider e6698744 : RESTRICT AUTOMERGE Revoke URI permissions for specific document paths

+- Project: platform/packages/providers/MediaProvider

8dc44d72e : RESTRICT AUTOMERGE Use parameterised queries for photo picker search request queries 21270fd56 : RESTRICT AUTOMERGE Fix location redaction bypass for oversized XMP boxes. 50d220c20 : RESTRICT AUTOMERGE Improve preselcted media URI validation 87beb3978 : RESTRICT AUTOMERGE Fix MediaStore race condition for pending files 11009f380 : RESTRICT AUTOMERGE Fix ISO XMP location redaction bypass 43a7df879 : [RESTRICT AUTOMERGE] Restrict geolocation metadata access in SQL query clauses ebcbbeb31 : RESTRICT AUTOMERGE Revoke URI permissions on file path updates

+- Project: platform/packages/providers/TelephonyProvider

dde6dddc : TelephonyProvider: Fix SQL injection in projection and sortOrder 1fab99e9 : Filter MMS/SMS queries by subscription ID

+- Project: platform/packages/services/BuiltInPrintService

c343ebe : Limit media-supported values

+- Project: platform/packages/services/Telecomm

45a9ba77a : Fix privilege escalation in ACTION_CALL intent trampoline 84aa17aab : Fix MMI check bypass via leading whitespace in tel URI. c1104b6c1 : Update fix for initiating calls from work profile 668eb0726 : Remove serviceClassExists logic to address security vulnerability

+- Project: platform/packages/services/Telephony

ba3c68f02 : Fix StackOverflowError in SatelliteEntitlementController 7e3d27fd7 : [Telephony] Secure contact URI access in Call Forwarding 5ef227b0a : Restrict USSD requests to the subscription's associated user.

+- Project: platform/system/core

2de25eeaec : ashmem_test: Add tests related to memfd's size file seals 6297cab2c9 : ashmem: Only handle size-sealed memfds

+- Project: platform/system/fs/fs_mgr

666f09f0 : libfiemap: Return false in MapAllImages if metadata is missing

+- Project: platform/system/libfmq

f727482 : Reapply "Handle corrupted read/write pointers in read funcitons"

+- Project: platform/system/libufdt

70c2086 : libufdt: Fix stack overflow risk in vendor qsort