3184e06e737a : Fix silence-injection policy skip in VirtualAudioController
a5fd26078dba : [25Q2] Mitigate BAL bypass via Companion Device Manager
9444f519c4e5 : Fix a regression in ECM mode setting after package install
f4e7001b21fb : Fix boot-loop vulnerability in setPermissionGrantState
e8ef27e17d89 : Sanitize labels in GrantCredentialsPermissionActivity
74f5e6fa6a20 : aapt2: Sanitize Javadoc comments to prevent code injection
01f51483eb2f : Fix potential NPEs in PduParser.parsePartHeaders
a28fb127a57b : RESTRICT AUTOMERGE: Fix vulnerabilities in PduParser
01bff648b538 : ResStringPool: Validate styleCount and offsets
a0bd9f4b3d53 : Truncate long device admin descriptions
431c43bd57cc : Limit knownActivityEmbeddingCerts in manifest
c47530a0f8f4 : Use byte count rather than string length for NMS component name check
e5560bd1d0c2 : SystemUi UsbDialog: fix label vulnerability
35058d93a551 : Fix path traversal and missing ownership check in LocaleManagerService
b159c903dc1d : Add Task-level input sink to block cross-task tap pass-through
8c6681692185 : Move input sink on top of the Activity when needed
0209580ab87a : Check notification permission in getAuthToken(notifyOnAuthFailure).
cf0b6cd90ce0 : Add size validation and trimming for ShortcutInfo objects.
2e7f56e02d86 : Hide media on smartspace view when setting is disabled
84d85dbe121f : RESTRICT AUTOMERGE Fix security vulnerability in getManageSpaceActivityIntent
63f908ebd9ee : Validate caller UID in openProxyFileDescriptor
91cf2b3195ed : Add bracket checking support to SQLiteTokenizer
794ac2765d10 : [LocalImageResolver] Fix security check bypass
05c5903d27b8 : Fix BAL bypass via getAppMarketActivityIntent
3d614f9e98a3 : LauncherApps: Scrub sensitive URIs in install sessions
fb6a81e33d54 : Autofill SaveUi URL validation and FLAG_IMMUTABLE
6fe346abe6fb : Remove usage of Parcel.allowSquashing in RemoteViews and immediate unparceling of Bundle
0e9656e2222e : Revert^2 "Writing ApplicationInfoCache instead of multiple ApplicationInfos for nested RemoteViews"
b61562e1abe6 : Fix using the base type for checking
8c2ce8c567a2 : Properly parse meta_key in AccountsDb.
cabd39ad7bd1 : Security bug fix: Prevent USB data changes for non-owner users during lockdown mode.
e95170c6378e : Harden startNextMatchingActivity() caller identity propagation.
a660d0c46482 : Don't parse 3p recognizer metadata in safe mode
2f86ea93fcdd : Fix FGS mode in test
dba6ec2c05ff : Validate caller in SlicePermissionActivity to prevent spoofing.
353a1fa497d3 : Update URI permission granting logic in Intent Redirection Hardening
5e717959bef1 : Restrict VirtualDeviceImpl methods to device owner.
7d8be5eb6753 : Sanitize intent selector in IntentForwarderActivity
71d6dc109528 : Fix & speed up IntentForwarderActivityTest
f2a29f4351f8 : RESTRICT AUTOMERGE [ExternalStorageProvider] Revoke URI permissions by path
c9290fc206ca : Use setHideOverlayWindows instead of AppOpsManager
80b1b1fe63b5 : DO NOT MERGE: [ClipboardService] Check notification setting for given user
581fd9950f41 : Catch OutOfMemoryError while parsing xml in GameManagerService
585e7556fcec : Fix URI grant persistence bypass
f7398bb64526 : Move intent redirect checks before intent resolution.
5108d2606324 : Fix intent redirect bypass via selector in addCreatorToken
8785e148ca82 : RESTRICT AUTOMERGE Filter ignorable Unicode codepoints in ExternalStorageProvider
bc676d257ca0 : Fix entryadapter usage
98be98fe443d : Make destAddr nullable
de08a320e58b : Set hide overlays on mini resolver
2b8a07bf7437 : Disallow launch-behind animation if BAL blocks
2e158f2d9a81 : Refactor: Add permission checks to Unarchive activities