{"id":"ASB-A-365738306", "published":"2025-01-01T00:00:00Z", "modified":"2026-04-30T15:48:46.890647439Z", "aliases":["CVE-2024-49733", "A-365738306"], "details":"In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "affected":[{"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"15-next:0"}, {"fixed":"15-next:2025-01-01"}]}], "versions":["15-next"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/234c5e843ca427b1dd47e91e3969f3309dd787bf"], "severity":"High", "spl":"2025-01-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["245706110952212737133143465215893512596", "8441015199286482723336096750019537574", "2203913801863013953610752326245761403", "168375376327039914811458805262559478873", "312734769563607363589114740525208817475", "3544166106377321621015066667677101117", "122966738851768452280672697718876528501", "120617789216700098775887114430797222613", "221077498712494506088861152745117288869", "334665111517373998642314040845320111876", "201576591833870305689470499159667889194", "298517652061270037363155204858969091800", "61803440693266216200337439482150002281", "87053992900134142751070947667173104721", "190583663821423385762165115122030327892", "125850764841171638689555196333133084999", "155670773850368399915527063221630377781", "250238567097922551481524748322810142350", "31221265380436497012317990031515028462", "196667568110689903248999351757630874598"], "threshold":0.9}, "id":"ASB-A-365738306-2767a15f", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/234c5e843ca427b1dd47e91e3969f3309dd787bf", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"}}, {"deprecated":false, "digest":{"function_hash":"264098323083350367885933473336084744836", "length":889}, "id":"ASB-A-365738306-cedaf568", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/234c5e843ca427b1dd47e91e3969f3309dd787bf", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java", "function":"reload"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"12:0"}, {"fixed":"12:2025-01-01"}]}], "versions":["12"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"], "severity":"High", "spl":"2025-01-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"264098323083350367885933473336084744836", "length":889}, "id":"ASB-A-365738306-745a2e79", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java", "function":"reload"}}, {"deprecated":false, "digest":{"line_hashes":["245706110952212737133143465215893512596", "8441015199286482723336096750019537574", "2203913801863013953610752326245761403", "168375376327039914811458805262559478873", "312734769563607363589114740525208817475", "3544166106377321621015066667677101117", "122966738851768452280672697718876528501", "120617789216700098775887114430797222613", "221077498712494506088861152745117288869", "334665111517373998642314040845320111876", "201576591833870305689470499159667889194", "298517652061270037363155204858969091800", "61803440693266216200337439482150002281", "87053992900134142751070947667173104721", "190583663821423385762165115122030327892", "125850764841171638689555196333133084999", "155670773850368399915527063221630377781", "250238567097922551481524748322810142350", "31221265380436497012317990031515028462", "196667568110689903248999351757630874598"], "threshold":0.9}, "id":"ASB-A-365738306-7c884d9a", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"12L:0"}, {"fixed":"12L:2025-01-01"}]}], "versions":["12L"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"], "severity":"High", "spl":"2025-01-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"264098323083350367885933473336084744836", "length":889}, "id":"ASB-A-365738306-15bd7590", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java", "function":"reload"}}, {"deprecated":false, "digest":{"line_hashes":["245706110952212737133143465215893512596", "8441015199286482723336096750019537574", "2203913801863013953610752326245761403", "168375376327039914811458805262559478873", "312734769563607363589114740525208817475", "3544166106377321621015066667677101117", "122966738851768452280672697718876528501", "120617789216700098775887114430797222613", "221077498712494506088861152745117288869", "334665111517373998642314040845320111876", "201576591833870305689470499159667889194", "298517652061270037363155204858969091800", "61803440693266216200337439482150002281", "87053992900134142751070947667173104721", "190583663821423385762165115122030327892", "125850764841171638689555196333133084999", "155670773850368399915527063221630377781", "250238567097922551481524748322810142350", "31221265380436497012317990031515028462", "196667568110689903248999351757630874598"], "threshold":0.9}, "id":"ASB-A-365738306-7e35a1f6", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"15:0"}, {"fixed":"15:2025-01-01"}]}], "versions":["15"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/3c44dd35fd99b87e8754a2c67f29b221ef3f69a5"], "severity":"High", "spl":"2025-01-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"264098323083350367885933473336084744836", "length":889}, "id":"ASB-A-365738306-d31a4043", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/3c44dd35fd99b87e8754a2c67f29b221ef3f69a5", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java", "function":"reload"}}, {"deprecated":false, "digest":{"line_hashes":["245706110952212737133143465215893512596", "8441015199286482723336096750019537574", "2203913801863013953610752326245761403", "168375376327039914811458805262559478873", "312734769563607363589114740525208817475", "3544166106377321621015066667677101117", "122966738851768452280672697718876528501", "120617789216700098775887114430797222613", "221077498712494506088861152745117288869", "334665111517373998642314040845320111876", "201576591833870305689470499159667889194", "298517652061270037363155204858969091800", "61803440693266216200337439482150002281", "87053992900134142751070947667173104721", "190583663821423385762165115122030327892", "125850764841171638689555196333133084999", "155670773850368399915527063221630377781", "250238567097922551481524748322810142350", "31221265380436497012317990031515028462", "196667568110689903248999351757630874598"], "threshold":0.9}, "id":"ASB-A-365738306-de76d7a8", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/3c44dd35fd99b87e8754a2c67f29b221ef3f69a5", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"13:0"}, {"fixed":"13:2025-01-01"}]}], "versions":["13"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"], "severity":"High", "spl":"2025-01-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["245706110952212737133143465215893512596", "8441015199286482723336096750019537574", "2203913801863013953610752326245761403", "168375376327039914811458805262559478873", "312734769563607363589114740525208817475", "3544166106377321621015066667677101117", "122966738851768452280672697718876528501", "120617789216700098775887114430797222613", "221077498712494506088861152745117288869", "334665111517373998642314040845320111876", "201576591833870305689470499159667889194", "298517652061270037363155204858969091800", "61803440693266216200337439482150002281", "87053992900134142751070947667173104721", "190583663821423385762165115122030327892", "125850764841171638689555196333133084999", "155670773850368399915527063221630377781", "250238567097922551481524748322810142350", "31221265380436497012317990031515028462", "196667568110689903248999351757630874598"], "threshold":0.9}, "id":"ASB-A-365738306-b2133486", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"}}, {"deprecated":false, "digest":{"function_hash":"264098323083350367885933473336084744836", "length":889}, "id":"ASB-A-365738306-fb2c09cc", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java", "function":"reload"}}]}}, {"package":{"name":"platform/frameworks/base", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"14:0"}, {"fixed":"14:2025-01-01"}]}], "versions":["14"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"], "severity":"High", "spl":"2025-01-01", "types":["ID"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"264098323083350367885933473336084744836", "length":889}, "id":"ASB-A-365738306-23f02976", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java", "function":"reload"}}, {"deprecated":false, "digest":{"line_hashes":["245706110952212737133143465215893512596", "8441015199286482723336096750019537574", "2203913801863013953610752326245761403", "168375376327039914811458805262559478873", "312734769563607363589114740525208817475", "3544166106377321621015066667677101117", "122966738851768452280672697718876528501", "120617789216700098775887114430797222613", "221077498712494506088861152745117288869", "334665111517373998642314040845320111876", "201576591833870305689470499159667889194", "298517652061270037363155204858969091800", "61803440693266216200337439482150002281", "87053992900134142751070947667173104721", "190583663821423385762165115122030327892", "125850764841171638689555196333133084999", "155670773850368399915527063221630377781", "250238567097922551481524748322810142350", "31221265380436497012317990031515028462", "196667568110689903248999351757630874598"], "threshold":0.9}, "id":"ASB-A-365738306-504ab2be", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815", "target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2025-01-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/frameworks/base/+/8516dfb89f99fd119fa12045e5c88633ce7478b8"}]}