android-security-14.0.0_r28 to android-security-14.0.0_r29 AOSP changelog

This only includes the Android Open Source Project changes and does not include any changes in any proprietary components included by Google or any hardware manufacturer. The raw log was generated using a modified version of this script written by JBQ and improved by Al Sutton.

Please do not copy this without attribution to this site and JBQ for the original script.

+- Project: platform/art

f8f7936106 : Make the runtime-generated app image read-only

+- Project: platform/bionic

cd1be6e8b : Fix bad free when limit exceeded.

+- Project: platform/build

309c1e1cb3 : Version bump to USV1.230808.057 [core/build_id.mk] 544cfed9ec : Version bump to USV1.230808.056 [core/build_id.mk]

+- Project: platform/development

6aa9341a76 : Fix potential NPEs in PduParser.parsePartHeaders

+- Project: platform/external/dng_sdk

52ff589 : Update to DNG SDK 1.7.1 2502

+- Project: platform/external/exfatprogs

54cf500 : ANDROID: Fix fsck overflows when handling bad clu_count or vol_length fields. 20f47ac : ANDROID: Add support for building exfat tests.

+- Project: platform/external/freetype

51c2994ab : Fix heap underflow write in ft_smooth_raster_lcd ab9caf444 : * src/sfnt/ttcolr.c (tt_face_colr_blend_layer): Use FT_ALLOC_MULT.

+- Project: platform/external/libhevc

d9977ef : libhevcdec: Fix heap buffer overflow in ihevcd_get_tu_data_size

+- Project: platform/external/libpng

843457e59 : fix(arm): Resolve out-of-bounds read/write in NEON palette expansion

+- Project: platform/external/wpa_supplicant_8

0ce10247 : wpa_supplicant: Fix OOB read in get_eht_op_width 5de2705a : Fix heap OOB write in Robust AV SCS Response handler

+- Project: platform/frameworks/av

8cf7d2e993 : Fix race conditions in CryptoHal plugin usage f8520e699d : Fix type confusion in mediatuner service 6654633902 : Camera: Fix heap OOB read/write in camera mappers d74fdb8ae7 : RESTRICT AUTOMERGE Camera3StreamSplitter: Add bounds check for slot index 099e8f6889 : Fix MediaBuffer size-inflation off-by-32 bug d708d1ed11 : Fix OOB in DynamicsProcessing MBC band processing 7a05282afe : [media] Fix heap-buffer-overflow in AudioAttributes unmarshalling db3b431dd8 : [media] Fix heap out-of-bounds write in MatroskaSource::read

+- Project: platform/frameworks/base

8ded15ca0499 : Fix silence-injection policy skip in VirtualAudioController e7028d348ee5 : [udc-staging] Mitigate BAL bypass via Companion Device Manager 057ff07691a6 : Fix boot-loop vulnerability in setPermissionGrantState 129f80c33f1f : Sanitize labels in GrantCredentialsPermissionActivity bcba9a47c23e : Fix potential NPEs in PduParser.parsePartHeaders 8325de4e11e9 : RESTRICT AUTOMERGE: Fix vulnerabilities in PduParser 1eb9fc572c86 : ResStringPool: Validate styleCount and offsets fdeb1aefefd5 : Truncate long device admin descriptions 1453b34c0ea5 : Limit knownActivityEmbeddingCerts in manifest dc19b329d865 : Use byte count rather than string length for NMS component name check e5d1fb2c34ce : SystemUi UsbDialog: fix label vulnerability 2a2f6ec57954 : Fix path traversal and missing ownership check in LocaleManagerService a042adf88538 : Add Task-level input sink to block cross-task tap pass-through 7599b48d00ee : Move input sink on top of the Activity when needed b2142726cb61 : Check notification permission in getAuthToken(notifyOnAuthFailure). 01bf19b34e45 : Add size validation and trimming for ShortcutInfo objects. 8dd2f9d4de64 : Hide media on smartspace view when setting is disabled 51b647175642 : RESTRICT AUTOMERGE Fix security vulnerability in getManageSpaceActivityIntent 0d2ee8e16afc : Validate caller UID in openProxyFileDescriptor 9183bfe6574b : Add bracket checking support to SQLiteTokenizer a4ecf8724097 : [LocalImageResolver] Fix security check bypass 3519be0f11c7 : Autofill SaveUi URL validation and FLAG_IMMUTABLE ae484e3d7a20 : Remove usage of Parcel.allowSquashing in RemoteViews and immediate unparceling of Bundle aa6e28b4fd2d : Revert^2 "Writing ApplicationInfoCache instead of multiple ApplicationInfos for nested RemoteViews" ce479a9a57bd : Fix using the base type for checking 051431afaec5 : Properly parse meta_key in AccountsDb. 59a2f1fa1a7c : CVE-2025-22442: set profile user restrictions earlier bb7413247455 : Harden startNextMatchingActivity() caller identity propagation. 20ecd72dd4c8 : Don't parse 3p recognizer metadata in safe mode c6b5038a9e23 : Validate caller in SlicePermissionActivity to prevent spoofing. 96057a4e7e40 : Sanitize intent selector in IntentForwarderActivity 2fadc52d7f18 : Fix & speed up IntentForwarderActivityTest 58f827bf9397 : RESTRICT AUTOMERGE [ExternalStorageProvider] Revoke URI permissions by path c441211a26c9 : Use setHideOverlayWindows instead of AppOpsManager 6f90eac7f9e5 : DO NOT MERGE: [ClipboardService] Check notification setting for given user 12567c8df8f3 : Catch OutOfMemoryError while parsing xml in GameManagerService a8279722faf7 : Fix URI grant persistence bypass 2cd960f154ec : RESTRICT AUTOMERGE Filter ignorable Unicode codepoints in ExternalStorageProvider 2e8edff2ab34 : Make destAddr nullable cb471de52128 : Set hide overlays on mini resolver d94f8b27bc84 : Disallow launch-behind animation if BAL blocks

+- Project: platform/frameworks/opt/telephony

8ae36cfb0c : Fix ArrayIndexOutOfBoundsException in SIMRecords due to invalid EF_CFIS/EF_CFF a702397eed : Block in-call MMI execution for USSD requests. 2c10fa5199 : Add subscription-user association check.

+- Project: platform/hardware/interfaces

8858a5521b : AIDL CAS HAL: Fix incorrect mmap failure check

+- Project: platform/packages/apps/Car/Settings

cb28e38fe1 : Replace DeviceAdminInfo.loadDescription() with loadDescriptionSafe() 03a0f94014 : Check getLaunchedFromPackage for CE Storage ccb13e0864 : Use setHideOverlayWindows instead of AppOpsManager

+- Project: platform/packages/apps/ManagedProvisioning

65cfe16ed : Prevent Setup Wizard from starting provisioning if the device is already provisioned.

+- Project: platform/packages/apps/Settings

778a381887c : Replace DeviceAdminInfo.loadDescription() with loadDescriptionSafe() a88ca458720 : Sanitize sensitive BiometricsSettingsBase extra a94d23c2595 : Fix confused deputy in Bluetooth settings dashboard a101a6cf443 : Sanitize package labels in SettingsApplication cbe16fc73cc : [Settings] Avoid start wrong fragment from MobileNetworkActivity 0f9f6238cf2 : [Settings] Strip URI grant flags in AppRestrictionsFragment e115f770374 : Use setHideOverlayWindows instead of AppOpsManager 4b69be85e55 : [RESTRICT AUTOMERGE] Ensure remote device credential alias is used for action CONFIRM_REMOTE_DEVICE_CREDENTIAL.

+- Project: platform/packages/apps/TV

e64e4b90 : [LiveTv] Avoid Intent Redirection to permission protected Activities 738d2cc1 : [LiveTv] Fix Intent redirection issue in SetupPassthroughActivity 2e9c27ac : [LiveTV] Specify intent package for "Send Feedback"

+- Project: platform/packages/apps/TvSettings

014727fb26 : Use loadDescriptionSafe for DeviceAdmin descriptions. 0f3428291e : Use setHideOverlayWindows instead of AppOpsManager

+- Project: platform/packages/modules/Bluetooth

f2741f1c70f : GATT: Fix notifications sent to remote device without security checks 51b0cc33b16 : [RESTRICT AUTOMERGE] Fix SDP server heap buffer overflow e3dba33c968 : [RESTRICT AUTOMERGE] Enforce incoming CTKD security requirements 4f7ed05b166 : [RESTRICT AUTOMERGE] Fix heap buffer overflow in A2DP Opus decoder 3475f39c4c1 : Reject unsafe LE encryption key sizes 1ac33292ff3 : Handle concurrency issues in SDP record creation

+- Project: platform/packages/modules/IntentResolver

d07a326e : Sanitize alternate intents. 0ed9b52b : Sanitize intent selector in IntentForwarderActivity

+- Project: platform/packages/modules/adb

c7995e05 : [adb] Fix Use-After-Free in TLS handshake. e96f6790 : [adb] Document and harden async transport flow.

+- Project: platform/packages/providers/ContactsProvider

1ba2557a : Restrict max size for Note.NOTE field 3f606a02 : Prevent SQL injection in SelectionBuilder

+- Project: platform/packages/providers/DownloadProvider

8c7db117 : RESTRICT AUTOMERGE Fix ZWSP path bypass in DownloadProvider 8397bd24 : RESTRICT AUTOMERGE Fix DownloadProvider completed download security bypass c9b9ee7a : RESTRICT AUTOMERGE Fix path traversal vulnerability in DownloadStorageProvider fb453d9c : RESTRICT AUTOMERGE Revoke URI permissions for specific document paths

+- Project: platform/packages/providers/MediaProvider

93cf0194cf : RESTRICT AUTOMERGE Fix location redaction bypass for oversized XMP boxes. e27ea39d71 : RESTRICT AUTOMERGE Fix MediaStore race condition for pending files 277a42f643 : RESTRICT AUTOMERGE Revoke URI permissions on file path updates 15168c2e6f : RESTRICT AUTOMERGE Fix ISO XMP location redaction bypass

+- Project: platform/packages/providers/TelephonyProvider

e0b82b04 : TelephonyProvider: Fix SQL injection in projection and sortOrder 475853dd : Filter MMS/SMS queries by subscription ID

+- Project: platform/packages/services/BuiltInPrintService

2ec9f874 : Limit media-supported values

+- Project: platform/packages/services/Telecomm

4ac0b6201c : Check caller in CSW#queryRemoteConnectionServices 12f9b433c1 : Fix MMI check bypass via leading whitespace in tel URI. 48d04bd334 : Update fix for initiating calls from work profile 9639413a5d : Resolve cross account user ringtone validation.

+- Project: platform/packages/services/Telephony

787ad217f9 : [Telephony] Secure contact URI access in Call Forwarding 2a177c06ec : Restrict USSD requests to the subscription's associated user. d24a3491f0 : Prevent SDK Sandbox from bypassing isSystemApp check

+- Project: platform/system/incremental_delivery

b6d06e7 : [incfs] Reduce the stack buffer size for pread()

+- Project: platform/system/libfmq

452c5e9 : Reapply "Handle corrupted read/write pointers in read funcitons"

+- Project: platform/system/libufdt

bbc615c : libufdt: Fix stack overflow risk in vendor qsort

+- Project: platform/system/media

a9dc2a96 : Fix camera metadata entry capacity validation.