{"id":"ASB-A-447135012", "published":"2026-03-01T00:00:00Z", "modified":"2026-05-01T15:24:27.653932157Z", "aliases":["CVE-2026-0013", "A-447135012"], "details":"In setupLayout of PickActivity.java, there is a possible way to start any activity as a DocumentsUI app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "affected":[{"package":{"name":"platform/packages/apps/DocumentsUI", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"16-qpr2-next:0"}, {"fixed":"16-qpr2-next:2026-03-01"}]}], "versions":["16-qpr2-next"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/32d6a7338dc3f655832c2832dc93d2cc66a2021e"], "severity":"High", "spl":"2026-03-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["103502400345607294393142118702258590127", "264578776238228467373563782560745062698", "38333945831087452299655159235332406990", "125995445259084665981549517189839964459"], "threshold":0.9}, "id":"ASB-A-447135012-519c4105", "match_only_versions":["16-qpr2-next"], "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/32d6a7338dc3f655832c2832dc93d2cc66a2021e", "target":{"file":"src/com/android/documentsui/picker/PickActivity.java"}}, {"deprecated":false, "digest":{"function_hash":"156743767400915202046690974386472525007", "length":1678}, "id":"ASB-A-447135012-b9003726", "match_only_versions":["16-qpr2-next"], "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/32d6a7338dc3f655832c2832dc93d2cc66a2021e", "target":{"file":"src/com/android/documentsui/picker/PickActivity.java", "function":"setupLayout"}}]}}, {"package":{"name":"platform/packages/apps/DocumentsUI", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"15:0"}, {"fixed":"15:2026-03-01"}]}], "versions":["15"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/550b1a413361b58511a92c0e4a451c5efd0945f1"], "severity":"High", "spl":"2026-03-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"line_hashes":["103502400345607294393142118702258590127", "264578776238228467373563782560745062698", "38333945831087452299655159235332406990", "111416144613965476055017657672312028260"], "threshold":0.9}, "id":"ASB-A-447135012-9cef64bf", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/550b1a413361b58511a92c0e4a451c5efd0945f1", "target":{"file":"src/com/android/documentsui/picker/PickActivity.java"}}, {"deprecated":false, "digest":{"function_hash":"210208562606341878581047640278892643461", "length":1240}, "id":"ASB-A-447135012-bb1baa77", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/550b1a413361b58511a92c0e4a451c5efd0945f1", "target":{"file":"src/com/android/documentsui/picker/PickActivity.java", "function":"setupLayout"}}]}}, {"package":{"name":"platform/packages/apps/DocumentsUI", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"16:0"}, {"fixed":"16:2026-03-01"}]}], "versions":["16"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/8eebea12db1815135398dfcc4c0276966c2790f9"], "severity":"High", "spl":"2026-03-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"120162466560451992709576043753057550201", "length":1460}, "id":"ASB-A-447135012-36b499ce", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/8eebea12db1815135398dfcc4c0276966c2790f9", "target":{"file":"src/com/android/documentsui/picker/PickActivity.java", "function":"setupLayout"}}, {"deprecated":false, "digest":{"line_hashes":["103502400345607294393142118702258590127", "264578776238228467373563782560745062698", "38333945831087452299655159235332406990", "111416144613965476055017657672312028260"], "threshold":0.9}, "id":"ASB-A-447135012-9f4b7c3d", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/8eebea12db1815135398dfcc4c0276966c2790f9", "target":{"file":"src/com/android/documentsui/picker/PickActivity.java"}}]}}, {"package":{"name":"platform/packages/apps/DocumentsUI", "ecosystem":"Android"}, "ranges":[{"type":"ECOSYSTEM", "events":[{"introduced":"14:0"}, {"fixed":"14:2026-03-01"}]}], "versions":["14"], "ecosystem_specific":{"fixes":["https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/631cfe0fc0bddaea1ff7dade5f9c1ac46100d91b"], "severity":"High", "spl":"2026-03-01", "types":["EoP"], "vanir_signatures":[{"deprecated":false, "digest":{"function_hash":"62780047556389138076162461782259110862", "length":1009}, "id":"ASB-A-447135012-cb97d3d5", "signature_type":"Function", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/631cfe0fc0bddaea1ff7dade5f9c1ac46100d91b", "target":{"file":"src/com/android/documentsui/picker/PickActivity.java", "function":"setupLayout"}}, {"deprecated":false, "digest":{"line_hashes":["103502400345607294393142118702258590127", "321784852465166673021149462032257623205", "273463559620289439968745718978014284962", "231780973864924926929498320679730924075"], "threshold":0.9}, "id":"ASB-A-447135012-ded5e133", "signature_type":"Line", "signature_version":"v1", "source":"https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/631cfe0fc0bddaea1ff7dade5f9c1ac46100d91b", "target":{"file":"src/com/android/documentsui/picker/PickActivity.java"}}]}}], "references":[{"type":"ADVISORY", "url":"https://source.android.com/security/bulletin/2026-03-01"}, {"type":"FIX", "url":"https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/9f2d3f09f8fdc099d5a2d4c8bf3e8ec460bb9233"}]}