android-security-15.0.0_r16 to android-security-15.0.0_r17 AOSP changelog

This only includes the Android Open Source Project changes and does not include any changes in any proprietary components included by Google or any hardware manufacturer. The raw log was generated using a modified version of this script written by JBQ and improved by Al Sutton.

Please do not copy this without attribution to this site and JBQ for the original script.

+- Project: platform/art

19665de3fb : Make the runtime-generated app image read-only

+- Project: platform/bionic

10a1e2ce6 : Fix bad free when limit exceeded.

+- Project: platform/build

59dc764f37 : Version bump to ASV1.240715.051 [core/build_id.mk] c410dfab9f : Version bump to ASV1.240715.050 [core/build_id.mk] 93195cb454 : Version bump to ASV1.240715.049 [core/build_id.mk] 821dee79b9 : Version bump to ASV1.240715.048 [core/build_id.mk]

+- Project: platform/development

59bbdb0ddd : Fix potential NPEs in PduParser.parsePartHeaders

+- Project: platform/external/dng_sdk

a23ee6a : Update to DNG SDK 1.7.1 2502

+- Project: platform/external/exfatprogs

ad27308 : ANDROID: Fix fsck overflows when handling bad clu_count or vol_length fields. 2957a37 : ANDROID: Add support for building exfat tests.

+- Project: platform/external/freetype

fc6e20766 : Fix heap underflow write in ft_smooth_raster_lcd 9f67316aa : * src/sfnt/ttcolr.c (tt_face_colr_blend_layer): Use FT_ALLOC_MULT. 2e564343a : [ttgxvar] Check for overflow in array size computation.

+- Project: platform/external/libhevc

c43bbf8 : libhevcdec: Fix heap buffer overflow in ihevcd_get_tu_data_size

+- Project: platform/external/libpng

fa7e33a0a : fix(arm): Resolve out-of-bounds read/write in NEON palette expansion

+- Project: platform/external/wpa_supplicant_8

d14e657c : Fix heap OOB write in Robust AV SCS Response handler 234d2841 : wpa_supplicant: Fix OOB read in get_eht_op_width

+- Project: platform/frameworks/av

864123e86f : Fix race conditions in CryptoHal plugin usage 7ccb7033d4 : Fix type confusion in mediatuner service ff3f3a6b81 : Camera: Fix heap OOB read/write in camera mappers de6bd248af : RESTRICT AUTOMERGE Camera3StreamSplitter: Add bounds check for slot index 3d1f8cef9a : Fix MediaBuffer size-inflation off-by-32 bug 98e472f24d : Fix OOB in DynamicsProcessing MBC band processing c92a922039 : Fix signed overflow in convertCleanApertureToRect 2d627fe899 : [media] Fix heap-buffer-overflow in AudioAttributes unmarshalling f193723847 : [media] Fix heap out-of-bounds write in MatroskaSource::read

+- Project: platform/frameworks/base

a46c94ad2ccc : Fix silence-injection policy skip in VirtualAudioController 35a55a523145 : [24Q3] Mitigate BAL bypass via Companion Device Manager 49e1a4ba935f : Fix boot-loop vulnerability in setPermissionGrantState 78ff07aa12b8 : Sanitize labels in GrantCredentialsPermissionActivity e2b80df1360a : Fix potential NPEs in PduParser.parsePartHeaders b86eef8c2ffe : RESTRICT AUTOMERGE: Fix vulnerabilities in PduParser 8bbb435c9b25 : Truncate long device admin descriptions ed4eedc69050 : ResStringPool: Validate styleCount and offsets a6ff1f594051 : Limit knownActivityEmbeddingCerts in manifest d71cc08e7ad0 : Use byte count rather than string length for NMS component name check 8c99389ef61e : SystemUi UsbDialog: fix label vulnerability a508a0a4dba6 : Fix path traversal and missing ownership check in LocaleManagerService 03c1d8e34069 : Add Task-level input sink to block cross-task tap pass-through 6025638f24fa : Move input sink on top of the Activity when needed 7cdef410dc98 : Check notification permission in getAuthToken(notifyOnAuthFailure). df66a8f07d3b : Add size validation and trimming for ShortcutInfo objects. d0fbd46bea7c : Hide media on smartspace view when setting is disabled 8c8709a5ad8c : RESTRICT AUTOMERGE Fix security vulnerability in getManageSpaceActivityIntent bca099fcb293 : Validate caller UID in openProxyFileDescriptor e93df405837f : Add bracket checking support to SQLiteTokenizer 34dc06411439 : [LocalImageResolver] Fix security check bypass 6c6471fc4718 : Autofill SaveUi URL validation and FLAG_IMMUTABLE 498791aa27ab : LauncherApps: Scrub sensitive URIs in install sessions cddac11f862e : Remove usage of Parcel.allowSquashing in RemoteViews and immediate unparceling of Bundle 04faeb30ca94 : Revert^2 "Writing ApplicationInfoCache instead of multiple ApplicationInfos for nested RemoteViews" 38dbed092b9d : Properly parse meta_key in AccountsDb. e7890bc1f9c0 : CVE-2025-22442: set profile user restrictions earlier 18d845a1ee4b : Fix FGS mode in test 971f1d196295 : Validate caller in SlicePermissionActivity to prevent spoofing. 8130b6057817 : Fix using the base type for checking fc3f36a616a3 : Security bug fix: Prevent USB data changes for non-owner users during lockdown mode. ba9c05f37043 : Harden startNextMatchingActivity() caller identity propagation. df4d44965279 : Don't parse 3p recognizer metadata in safe mode 577f0333c2c3 : Sanitize intent selector in IntentForwarderActivity 323651e81585 : Fix & speed up IntentForwarderActivityTest aedf5f0fa70f : RESTRICT AUTOMERGE [ExternalStorageProvider] Revoke URI permissions by path 90ce24ef3760 : Use setHideOverlayWindows instead of AppOpsManager 993d9100be4c : DO NOT MERGE: [ClipboardService] Check notification setting for given user 47898903e7c3 : Catch OutOfMemoryError while parsing xml in GameManagerService 1fcacc7ecb60 : Fix URI grant persistence bypass b94ba8571216 : RESTRICT AUTOMERGE Filter ignorable Unicode codepoints in ExternalStorageProvider d09bfc5ee8b4 : Make destAddr nullable 8e66b48894f7 : Set hide overlays on mini resolver d98cb1490fc3 : Disallow launch-behind animation if BAL blocks a4b48c54049c : Refactor: Add permission checks to Unarchive activities

+- Project: platform/frameworks/opt/telephony

64d94aa15e : Fix ArrayIndexOutOfBoundsException in SIMRecords due to invalid EF_CFIS/EF_CFF 92836c48ba : Block in-call MMI execution for USSD requests. 3ed5e1fdd5 : Add subscription-user association check.

+- Project: platform/hardware/interfaces

9bdc5c54c7 : AIDL CAS HAL: Fix incorrect mmap failure check

+- Project: platform/packages/apps/Car/Settings

f9b731471a : Replace DeviceAdminInfo.loadDescription() with loadDescriptionSafe() b2d58f33fb : Check getLaunchedFromPackage for CE Storage 084a3e3538 : Use setHideOverlayWindows instead of AppOpsManager

+- Project: platform/packages/apps/ManagedProvisioning

fc97ea693 : Prevent Setup Wizard from starting provisioning if the device is already provisioned.

+- Project: platform/packages/apps/Settings

8bdb3c884b6 : Replace DeviceAdminInfo.loadDescription() with loadDescriptionSafe() 783b7806995 : Sanitize sensitive BiometricsSettingsBase extra 0656c1bc9bc : Fix confused deputy in Bluetooth settings dashboard 60b2a8568ca : Sanitize package labels in SettingsApplication fb6aebafa1e : [Settings] Avoid start wrong fragment from MobileNetworkActivity 856f8ccca12 : [Settings] Strip URI grant flags in AppRestrictionsFragment cc183b2887e : Use setHideOverlayWindows instead of AppOpsManager 1d0237d77a3 : Remove dialog building logic from PaymentDefaultDialog onCreate. 839f9278396 : [RESTRICT AUTOMERGE] Ensure remote device credential alias is used for action CONFIRM_REMOTE_DEVICE_CREDENTIAL.

+- Project: platform/packages/apps/TV

481a7a58 : [LiveTv] Avoid Intent Redirection to permission protected Activities f23429d7 : [LiveTv] Fix Intent redirection issue in SetupPassthroughActivity 7e516e62 : [LiveTV] Specify intent package for "Send Feedback"

+- Project: platform/packages/apps/TvSettings

540f4ec31c : Use loadDescriptionSafe for DeviceAdmin descriptions. 7a21141ea7 : Use setHideOverlayWindows instead of AppOpsManager

+- Project: platform/packages/modules/Bluetooth

e1838387644 : GATT: Fix notifications sent to remote device without security checks c738041c8ce : [RESTRICT AUTOMERGE] Fix SDP server heap buffer overflow eb524b72724 : [RESTRICT AUTOMERGE] Enforce incoming CTKD security requirements b837ddeb712 : [RESTRICT AUTOMERGE] Fix heap buffer overflow in A2DP Opus decoder 9b196f44770 : Remove bond caller info when bonding concludes f161543f33d : Reject unsafe LE encryption key sizes 5a95b20635a : Handle concurrency issues in SDP record creation

+- Project: platform/packages/modules/IntentResolver

3a931500 : Sanitize alternate intents. 2772217b : Sanitize intent selector in IntentForwarderActivity

+- Project: platform/packages/modules/Wifi

5dab8604e9 : Fix persistent DoS in WifiNetworkSuggestionsManager via PersistableBundle depth bomb

+- Project: platform/packages/modules/adb

119250e4 : [adb] Fix Use-After-Free in TLS handshake. cadd481e : [adb] Document and harden async transport flow.

+- Project: platform/packages/providers/ContactsProvider

f71ae192 : Restrict max size for Note.NOTE field b8e00892 : Prevent SQL injection in SelectionBuilder

+- Project: platform/packages/providers/DownloadProvider

58e8f2d8 : RESTRICT AUTOMERGE Fix ZWSP path bypass in DownloadProvider 842086d9 : RESTRICT AUTOMERGE Fix DownloadProvider completed download security bypass 1975d36d : RESTRICT AUTOMERGE Fix path traversal vulnerability in DownloadStorageProvider 4a47b19b : RESTRICT AUTOMERGE Revoke URI permissions for specific document paths

+- Project: platform/packages/providers/MediaProvider

ec0834680b : RESTRICT AUTOMERGE Fix location redaction bypass for oversized XMP boxes. 1b032be599 : RESTRICT AUTOMERGE Improve preselcted media URI validation 9e42f05c7c : RESTRICT AUTOMERGE Fix MediaStore race condition for pending files 5474b6871d : RESTRICT AUTOMERGE Revoke URI permissions on file path updates cb04f3531f : RESTRICT AUTOMERGE Fix ISO XMP location redaction bypass

+- Project: platform/packages/providers/TelephonyProvider

854197b2 : TelephonyProvider: Fix SQL injection in projection and sortOrder 4fab244b : Filter MMS/SMS queries by subscription ID

+- Project: platform/packages/services/BuiltInPrintService

b82964c3 : Limit media-supported values

+- Project: platform/packages/services/Telecomm

8adbb86845 : Check caller in CSW#queryRemoteConnectionServices ec63a79133 : Update fix for initiating calls from work profile 34f4edcdb5 : Fix MMI check bypass via leading whitespace in tel URI. 0d4024bee0 : Resolve cross account user ringtone validation.

+- Project: platform/packages/services/Telephony

5b53784d2d : Fix StackOverflowError in SatelliteEntitlementController 40d1716b10 : [Telephony] Secure contact URI access in Call Forwarding 83d27ac3f3 : Restrict USSD requests to the subscription's associated user. e27c804e5b : Fixed the UT build error in CarrierConfigLoaderTest.java. f4699b1d48 : Prevent SDK Sandbox from bypassing isSystemApp check

+- Project: platform/system/incremental_delivery

877702e : [incfs] Reduce the stack buffer size for pread()

+- Project: platform/system/libfmq

6d316ed : Reapply "Handle corrupted read/write pointers in read funcitons"

+- Project: platform/system/libufdt

109d689 : libufdt: Fix stack overflow risk in vendor qsort

+- Project: platform/system/media

9b4fe9dc : Fix camera metadata entry capacity validation.