2024 年度补丁分析:点我
2025 年度补丁分析:点我

我是 2025 年 Android VRP 冠军!点这里看我的名字: https://bughunters.google.com/blog/google-vrps-in-review-2025#android-devices

最后更新时间:2026/10/05 更新内容:更新 2026-09-01

2026-09-01

没给17更新的洞全都没贴补丁链接,想累死我是吧
之前电脑坏了导致更新延迟,说一声抱歉

完全人工分析,拒绝 AI 幻觉,质量有保证,这都不关注我吗

Android Runtime

CVE-2026-28664 EoP High
创建 runtime generated ART image 的时候把它标记为不可写,这些文件放在 cache 下面,是 app 可写的目录,所以如果宿主 app 存在文件写漏洞(比如路径穿越)就能覆写 art 文件进而转换为代码执行。
https://www.offensivecon.org/speakers/2026/philipp-mao-and-rokhaya-fall.html
https://www.youtube.com/watch?v=FikuvF6Ot_E

Framework

CVE-2026-28666 EoP Critical
我报的洞,之前 CVE-2026-0049 的修复在 LocalImageResolver 里加了 mime type 检查,拒绝解码 dng 文件,但是 SystemUI 在渲染通知的时候有一个 preload 步骤,会提前预加载要渲染的图片,这条路径里就没有 mime type 检查,导致绕过。我当时只证明了在 SystemUI 里触发 dng_sdk ubsan 崩溃,应该是 Google 考虑到这个绕过如果跟 dng 解码器的内存漏洞组合在一起可能导致特权进程 RCE 所以给的是 EoP。

CVE-2026-55273 EoP Critical
aapt2 处理 javadoc 的时候过滤掉 */ 等字符,可以提前结束注释然后注入任意代码,供应链攻击。
原来这种问题他们也认的吗?

CVE-2026-49932 DoS Critical
telephony PduParser 解析彩信的时候可能发生多种异常导致进程崩溃。

CVE-2026-28609 RCE High
公告未包含补丁链接,手动还原得到:
https://android.googlesource.com/platform/frameworks/av/+/db3b431dd8aa0ba006499d20fe3cd607c40ac9ad

提交信息已经说的很清楚了,这里直接贴上来,又是被 C 类型坑的一集

1
2
3
4
5
6
7
8
9
10
11
[media] Fix heap out-of-bounds write in MatroskaSource::read

The root cause was incorrect pointer arithmetic where a byte-level
offset (frame->range_offset()) was added directly to a uint16_t*
pointer. This caused the effective byte offset to be doubled (scaled by
the size of uint16_t), leading the subsequent ntohs() operation to write
past the end of the allocated buffer.

This change corrects the pointer arithmetic by casting the data pointer
to uint8_t* before applying the range offset, ensuring the pointer
advances by the correct number of bytes.
1
2
3
4
5
6
7
8
9
10
             if (bigEndian == 1 && bitPerFrame == 16) {
// Big-endian -> little-endian
- uint16_t *dstData = (uint16_t *)frame->data() + frame->range_offset();
- uint16_t *srcData = (uint16_t *)frame->data() + frame->range_offset();
+ uint16_t *data = (uint16_t *)((uint8_t *)frame->data() + frame->range_offset());
for (size_t i = 0; i < frame->range_length() / 2; i++) {
- dstData[i] = ntohs(srcData[i]);
+ data[i] = ntohs(data[i]);
}
}

CVE-2025-48564 EoP High
CVE-2025-48566 EoP High
去年的 CVE-2025-48564/48566,带上测试修复和 https://android.googlesource.com/platform/frameworks/base/+/96057a4e7e4000f8b2e6a59d1d064d376083ef86 然后重新放一遍

CVE-2026-0010 EoP High
又是重播,老活新整

CVE-2026-0065 EoP High
https://android.googlesource.com/platform/frameworks/base/+/407d7b0830109236c9558ac3d9ca55e5fc729ff4
阻止只有 PIP 窗口的 app 启动 activity

CVE-2026-28572 EoP High
https://cs.android.com/android/_/android/platform/frameworks/base/+/47ac32cb93e7739fa5dcb9fac8de912661ed675f
PackageInstaller 的 v2 页面忘记添加点按劫持保护

CVE-2026-28594 EoP High
ashmem 使用 memfd 前确保它的大小已经 seal 过了,防止在使用时另一个进程改变它的大小造成竞态条件

CVE-2026-28599 EoP High
Intent Redirection Hardening 中的逻辑错误,intent.getPackage() != null 并不代表这个 intent 一定会被解析到对应 package,因为 selector 更优先,会导致 creator token 直接被跳过添加。

CVE-2026-28607 EoP High
PackageInstaller Unarchive app 相关 activity 先检查调用方的 REQUEST_INSTALL_PACKAGES 和 INSTALL_PACKAGES 再跳转到 v2 实现,同时给 UnarchiveErrorActivity 加上 SYSTEM_FLAG_HIDE_NON_SYSTEM_OVERLAY_WINDOWS。

CVE-2026-28612 EoP High
Intent Redirection Hardening 的检查放在 resolveActivity 前面,因为 resolveActivity 可能改变 intent 的 component。

CVE-2026-28614 EoP High
SlicePermissionActivity 只允许被 SystemUI/android/被请求授权的 provider 所属包启动。
其实我不是很懂这有什么问题,mCallingPkg 确实来自 intent extras,但是伪造了 mCallingPkg 就会导致权限被授权到对应 app 才对

CVE-2026-28620 EoP High
Intent Redirection Hardening ,只有 calling uid 和 intent creator 同时允许访问 uri 才触发授权

CVE-2026-28631 EoP High
https://android.googlesource.com/platform/frameworks/base/+/426df92120398800fc185c7540f6263a58cbea2d%5E%21/#F0
给 IntentForwarderActivity 隐藏悬浮窗

CVE-2026-28642 EoP High
https://android.googlesource.com/platform/frameworks/base/+/34bbada3964e240057515958c510ed26f539d527
如果 BAL 策略阻止 activity 启动,忽略 mLaunchTaskBehind

CVE-2026-28644 EoP High
https://android.googlesource.com/platform/frameworks/base/+/995f95376eb373d9e8d584883a87ebb90db609d0
startNextMatchingActivity() 可以伪造 getLaunchedFromPackage(),我报的洞,但是在补丁出来前已经被其他人公开了,可以看
https://konata.github.io/posts/identity-squashing/

CVE-2026-28650 EoP High
app 被 suspend 而隐藏悬浮窗时如果是子窗口,需要看 base 窗口的 type 而不是子窗口自己的。

CVE-2026-28655 EoP High
https://android.googlesource.com/platform/frameworks/base/+/b78e053388018e2dc8be512eda8660e190759a55
RemoteViews 停止使用 Parcel ReadWriteHelper,见
https://blog.canyie.top/2026/06/09/android-security-tricks/#%E5%88%A9%E7%94%A8-ReadWriteHelper-%E4%BB%BB%E6%84%8F%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96

CVE-2026-28656 EoP High
https://android.googlesource.com/platform/frameworks/base/+/740cb9e8f2e4bafac209c865b3b304b0b4731d00
https://android.googlesource.com/platform/packages/apps/Settings/+/29a720d9f2e44a8d92a6954a7a26e7f4847c536c
https://android.googlesource.com/platform/packages/apps/TvSettings/+/c5f056067eb6d0f2ca3d2502bcee798c99cd2ef2
https://android.googlesource.com/platform/packages/apps/Car/Settings/+/53fe03113a5e8fcf93cb3502c9de056956aaedd7
https://android.googlesource.com/platform/packages/apps/Car/Settings/+/3db89f187b25c9094463df38e7f71a4d5dd8a235
把以往依赖 AppOps 隐藏悬浮窗的代码改成使用标准的 SYSTEM_FLAG_HIDE_NON_SYSTEM_OVERLAY_WINDOWS

CVE-2026-28657 EoP High
AppWidgetConfigActivityProxy 返回的 intent 只带 extras,去掉 URI grant flags

CVE-2026-28658 EoP High
AccountsDb 里把用 split(":") 获取 type 的代码改成使用 substring,看描述是 frp bypass,猜测是在 type 里嵌入 : 让代码取到不完整的 type。

CVE-2026-28663 EoP High
LauncherAppsService.getAppMarketActivityIntent() 用 system server 权限创建 PendingIntent 然后返回给 app,app 可以把它设置在 notification 的 deleteIntent 里,发送 notification 然后在通知被取消时触发 deleteIntent 被 system_server send,然后创建者和发送者都是 system 绕过 BAL 限制。补丁在创建 PendingIntent 时指定 MODE_BACKGROUND_ACTIVITY_START_ALLOW_IF_VISIBLE 让它忽略 system uid 的特权。

CVE-2026-45518 EoP High
官方公告少放了一个提交:
https://android.googlesource.com/platform/packages/providers/ContactsProvider/+/5ec4850fbe73949e42b016b6063bf025fd92337a
给 SQLiteTokenizer 添加支持以检测不平衡括号,然后在 ContactsProvider 内使用该功能以阻止 SQL 注入。

CVE-2026-45528 EoP High
StorageManagerService.getManageSpaceActivityIntent() 使用 ActivityManagerInternal.getPendingIntentActivityAsApp() 代替原来的 clearCallingIdentity() + createPackageContextAsUser(),修改之前的代码构造的 PendingIntent 是系统特权身份,修改之后是被调 app 的身份。看描述是 Launch Anywhere chain。

CVE-2026-49887 EoP High
PackageInstaller v2 里把权限判断写反了,!isPermissionGranted 漏掉了 !。

CVE-2026-58874 EoP High
https://android.googlesource.com/platform/frameworks/base/+/c6e940d710fbd4383f2e999f4d1a2234c0ae11dc
https://android.googlesource.com/platform/frameworks/opt/telephony/+/6cffd2ed55767990357cf11ab54718954ac6d961
发送短信的时候检查调用用户与 SIM 卡之间有关联。

CVE-2026-0054 ID High
https://android.googlesource.com/platform/frameworks/base/+/2ecd01f868b7b8c39f46428d03770c00e0749b72
SystemUI WalletContextualLocationsService 只允许 SYSTEM_UI_INTELLIGENCE 角色的特权持有者调用。

CVE-2026-28602 ID High
ClipboardService 读 Settings Provider 带上正确的用户,保证主用户关了 CLIPBOARD_SHOW_ACCESS_NOTIFICATIONS 不会影响到其他用户。

CVE-2026-28660 ID High
LauncherApps.getAllPackageInstallerSessions() 返回的结果里过滤 originatingUri 和 referrerUri。

CVE-2026-45521 ID High
StorageManagerService.openProxyFileDescriptor() 只允许 mountId 的所有者调用。

CVE-2026-55290 ID High
资源解析过程中的越界读,加上对 stringsStart stylesStart 等相关字段的越界校验。

CVE-2026-28584 DoS High
我报的 CVE-2025-48569 的补丁绕过,原本通过 whitelistedRestrictedPermissions.retainAll(mPm.getAllPlatformRestrictedPermissions()) 限制 whitelistedRestrictedPermissions 的大小,但是 whitelistedRestrictedPermissions 实际上是一个 list,里面元素可以重复,把一个有效的权限重复多遍就可以绕过大小限制。补丁加了个去重。

CVE-2026-28596 DoS High
https://android.googlesource.com/platform/frameworks/base/+/d3a1cc8820b17b04723df14b9e5df02473f440d6
捕获 GameManagerService 解析 xml 过程中可能出现的 OOM。

CVE-2026-28633 DoS High
安全模式下跳过解析 RecognitionService meta data。

CVE-2026-45527 DoS High
media.extractor 进程中的整数溢出,应该只会造成临时拒绝服务才对,不知道为什么给高

System

CVE-2026-28604 RCE Critical
adb 无线调试鉴权过程中的 race 导致的 UAF 问题。

CVE-2026-28618 RCE Critical
libopenapv 中的缓冲区溢出

CVE-2026-28639 RCE Critical
NFC 里的越界写,似乎跟 CVE-2021-0430 有关?

CVE-2026-28662 RCE Critical
wpa_supplicant_8 中的越界写,同时给 libpasn 打开 bounds ubsan 以增强安全性

CVE-2026-49882 RCE Critical
CVE-2026-49884 RCE Critical
NFC rw_mfc_handle_read_op 里的又两个越界写

CVE-2026-49919 RCE Critical
freetype 里的整数溢出

CVE-2026-49921 RCE Critical
蓝牙 SDP 里的多个缓冲区溢出

CVE-2026-27280 EoP Critical
https://android.googlesource.com/platform/external/dng_sdk/+/51fac39e7e2a05b2c5fa54108035d0140a5bc86c
升级 DNG SDK 到 1.7.1 2502

CVE-2026-28590 EoP Critical
https://android.googlesource.com/platform/packages/modules/Bluetooth/+/55c96018e4b47ef96f52d8a5696922e406228051
蓝牙里拒绝长度小于7的key

CVE-2026-33636 EoP Critical
libpng 里的越界读写

CVE-2026-45515 EoP Critical
蓝牙 A2DP Opus decoder 里的缓冲区溢出

CVE-2026-45531 EoP Critical
exfatprogs 中的整数溢出导致的越界读?

CVE-2026-49879 EoP Critical
nfc 里的整数溢出导致越界写

CVE-2026-49918 EoP Critical
libcupsfilters 分配缓冲区时的整数溢出

CVE-2026-49927 EoP Critical
libppd 里的整数溢出

CVE-2026-55277 EoP Critical
nfc RoutingManager::checkUiccListenConfigNeeded 函数里校验 nb_config 防止越界。

CVE-2026-55285 EoP Critical
NXP secure_element HAL 校验安全元件返回的 channel number 防止越界。

CVE-2026-58823 EoP Critical
NFC libstpropnci 添加更严格的边界检查。

CVE-2026-28653 DoS Critical
libnfc-nci 里的整数回绕造成的越界写

CVE-2026-49926 DoS Critical
给 libjxl 禁用 unsigned integer overflow UBSan

CVE-2026-55256 DoS Critical
https://android.googlesource.com/platform/frameworks/base/+/724976bd27bdfe7d64db47fa2dd1827e3e90ef68
PduParser 里的 NPE

CVE-2026-58822 RCE High
freetype 里的越界写

CVE-2025-48565 EoP High
去年分析过

CVE-2026-0008 EoP High
https://android.googlesource.com/platform/packages/apps/Settings/+/7ac22f2eae5d3e8e65bc7f8db5a173231ebba071
Settings FaceEnroll 被外部启动时忽略 EXTRA_ENROLL_AFTER_FACE,可能类似之前的 CVE-2025-32347

CVE-2026-0084 EoP High
https://android.googlesource.com/platform/packages/modules/Nfc/+/2711c9ef108434aa87e92a3de1e1b439f8d07c4f
NFC 修复 HCE 服务可能未被解绑导致 BAL 的 bug。我的可怜重复

CVE-2026-28583 EoP High
https://android.googlesource.com/platform/system/media/+/930c247918143f812a9ccb0b682dcacf482e44ec
cameraserver validate_camera_metadata_structure 校验不足导致的越界写

CVE-2026-28600 EoP High
PaymentDefaultDialog 不再接收外界传进来的 user id

CVE-2026-28603 EoP High
AppRestrictionsFragment 启动 intent 前去掉 URI grant flags

CVE-2026-28606 EoP High
https://android.googlesource.com/platform/packages/modules/Bluetooth/+/cb84e50dfff3de0fd9ef1a035f1d30ac0e2da615
蓝牙绑定被移除的时候清掉相关的状态信息,应该是防止后续有设备伪造相同的 mac 地址跳过确认弹窗

CVE-2026-28611 EoP High
https://android.googlesource.com/platform/packages/modules/Nfc/+/7b40ea922150f05b3ea067005a53400f2a313040
NFC Service 部分方法未检查传入的包名就直接使用了

CVE-2026-28624 EoP High
ConfirmDeviceCredentialActivity 不再返回受控 intent 防止 URI grant

CVE-2026-28634 EoP High
TelephonyManager.sendUssdRequest() 校验调用用户确实有权限操作对应 sim 卡

CVE-2026-28636 EoP High
https://android.googlesource.com/platform/packages/apps/DocumentsUI/+/32d6a7338dc3f655832c2832dc93d2cc66a2021e
补丁和之前的 CVE-2026-0013 是一样的。

CVE-2026-28668 EoP High
bionic realloc 里的错误 free。

CVE-2026-45520 EoP High
Settings BiometricsSettingsBase 被外界启动时忽略 EXTRA_USER_ID EXTRA_KEY_GK_PW_HANDLE。

CVE-2026-45529 EoP High
MmsSmsProvider 不返回和当前用户无关的 sim 卡的短信。

CVE-2026-49881 EoP High
2026 年最严重+最离谱 bug,可惜我的报告重复了
我们的 poc 和完整 writeup,可实现完整 root 提权:
https://github.com/LSPosed/LSPromise

CVE-2026-49913 EoP High
mmap 失败时返回 MMAP_FAILED 即 -1,因此检查 null 是不对的,修正判断阻止后续访问无效地址

CVE-2026-55294 EoP High
libhevcdec 里的缓冲区溢出

CVE-2026-58839 EoP High
https://android.googlesource.com/platform/system/incremental_delivery/+/07f1345a34d3b7dd2054f51730a3a2423d75feb2
把一个栈上缓冲区的大小从 128k 缩小成 32k,防止在接近爆栈的时候直接越过栈底的保护页,治标不治本
相关问题:
https://project-zero.issues.chromium.org/issues/465827985

CVE-2026-28581 ID High
https://android.googlesource.com/platform/packages/services/Telecomm/+/08564e5b3e2792fceba976e7cb7efdd7d13a5c80
telecom 使用 RoleManager 判断有没有默认拨号盘,提交信息已经说的很清楚了

CVE-2026-28582 ID High
android.app.action.CONFIRM_REMOTE_DEVICE_CREDENTIAL 需要 android.permission.CHECK_REMOTE_LOCKSCREEN 权限,修复 activity alias 可以被手动指定 component 绕过的问题。

CVE-2026-28622 ID High
MediaProvider 过滤尝试查询位置 metadata 的请求。

CVE-2026-28623 ID High
BleCsRangingCapabilities 和 BleRssiRangingCapabilities 被传出时不记录 mac 地址

CVE-2026-28627 ID High
如果蓝牙双方都支持 Secure Connections,拒绝非 secure 的连接。

CVE-2026-28630 ID High
我报的垃圾洞,给 ContactsPicker 添加点按劫持保护。

CVE-2026-28638 ID High
支持从使用了 BOX_XMP 的图片里过滤位置信息。

CVE-2026-28652 ID High
RangingServiceImpl OOB ranging API 添加权限检查。

CVE-2026-28671 ID High
MediaProvider 里的 race condition,没仔细看,需要深入研究

CVE-2026-45517 ID High
CVE-2026-45519 ID High
photo picker 对 app 传入的 preselected items 做更严格的检查,比如确保是 content URI,拥有合法的 Authority 和结构,不跨用户

CVE-2026-45525 ID High
支持从含有超过 1mb 的 XMP box 的图片里过滤位置信息。

CVE-2026-49895 ID High
wpa_supplicant8 中的越界读,最小长度被错误定义了

CVE-2026-28617 DoS High
添加 WifiNetworkSuggestion 时清空 vendor data,之前可以使用无限深度的 PersistableBundle 造成 dos

2026-09-05

TV

恭迎 TV 回归!

CVE-2026-28593 EoP High
TV SettingsFragment 使用显式 intent 代替隐式 intent,防止 intent 劫持

CVE-2026-28613 EoP High
拒绝打开被权限保护的 activity

CVE-2026-28626 EoP High
SetupPassthroughActivity 中的 intent redirection,增加 getLaunchedFromPackage() 校验并在被不可信 app 打开时直接 finish

2026-08-01

N/A

2026-08-05

Pixel

CVE-2026-0163 EoP High
https://project-zero.issues.chromium.org/issues/493643407

2026-07-01

咕咕嘎嘎

2026-06-01

CVE-2025-48595 在野利用
高通解锁节的命令注入洞 CVE-2026-24089 CVE-2026-24087 也在这个月被修

Framework

CVE-2025-65018 EoP Critical
CVE-2025-64720 DoS Critical
libpng 1.6.51 之前的堆缓冲区溢出 越界读写

CVE-2025-22424 EoP High
CVE-2025-22426 EoP High
去年放过的再放一遍,依旧没看懂

更新:看了一下,似乎是有 provider 声明 android:authorities="0@其他 provider 的 authority" 这种包含 user id 的格式的 authorities 的时候会出问题

CVE-2025-48570 EoP High
我跟 WeiMing Cheng 一块发现的洞,补丁是 SystemUI 没有及时响应就清掉 PIP task,实际利用起来还挺复杂的,最后效果是 bal

CVE-2025-48595 EoP High
升级到 sqlite 3.44.5

CVE-2025-48615 EoP High
去年我报的洞,第一次没修好,只限制了 PendingIntent component 的长度但是没有限制直接传进去的 component name 的长度,所以撤回重新放一遍

CVE-2025-48649 EoP High
App 自己清除自己的数据的时候不要重设权限,重设权限有可能会因为这个 app 是默认应用或者持有某些角色而导致被用户主动拒绝的权限被自动授予,这是非预期行为

CVE-2025-48652 EoP High
PackageInstaller 的修改,原来的代码是只要发起安装的 app 有 INSTALL_PACKAGES 权限就允许绕过 device policy manager 设定的禁止安装未知来源软件限制,现在改成还需要 intent action 不能是 ACTION_VIEW or ACTION_INSTALL_PACKAGE。怀疑是有系统 app 支持点击 apk 文件打开?但是 nfc 和蓝牙现在好像都没有 INSTALL_PACKAGES 权限

CVE-2026-0009 EoP High
PhotoPicker 选择照片时添加一个确认步骤

CVE-2026-0046 EoP High
WindowManagerService Letterbox (应用方向改变时环绕屏幕的方框) 的身份设置成 app 的身份而非 WindowManagerService 自己的身份,阻止 letterbox 上的点击穿透到下面的 activity。按理来说一个 Activity 下面应该有 ActivityRecordInputSink 接住可能穿透的点击事件的,是因为 letterbox 的 uid 被设置成 system uid 导致它被认为是可信窗口所以现有的防护没生效吗?

CVE-2026-0048 EoP High
隐藏非系统悬浮窗时如果它在播放退出动画,立刻隐藏它,否则 hide 会等待动画播放结束,可能需要很长时间

CVE-2026-0055 EoP High
创建 package install session 的时候检查传入的 volumeUuid,阻止路径穿越

CVE-2026-0061 EoP High
隐藏窗口时使用 app 拿不到的 SurfaceControl 设置显示状态

CVE-2026-0076 EoP High
资源解析的代码里面拒绝过小的 attrExt->attributeSize,会造成越界读

CVE-2026-0077 EoP High
补丁:
https://cs.android.com/android/_/android/platform/frameworks/base/+/407d0fcb459d11b1574e1ebe6ccc297a9d00c6b6
看描述是 BAL

CVE-2026-0078 EoP High
device admin app 设置代理时限制字符串长度

CVE-2026-0087 EoP High
修复 App Links 功能里 *.xyz.com 会匹配到任意以 xyz.com 结尾的域名(包括 abcxyz.com)的 bug
关于这个功能的文档:
https://developer.android.com/training/app-links/verify-applinks

CVE-2026-0089 EoP High
限制 clearDeveloperVerificationExperiment 接口调用者必须是 shell 或者 root,补丁:
https://cs.android.com/android/_/android/platform/frameworks/base/+/c15dea2dc3bb0ebeefeb59eb74290ac9fa918bf8

CVE-2026-0091 EoP High
我报的洞,具体见
https://github.com/canyie/TransitionPlayer

CVE-2026-0100 EoP High
解析 arsc 时拒绝大于 255 的 package id,否则会造成越界写

CVE-2026-28577 EoP High
添加 TYPE_TOAST 类型的窗口时如果对应的 token 已经有了其他 toast,拒绝添加

CVE-2026-28580 EoP High
NotificationChannel 内判断 VibrationEffect 是否需要裁剪的逻辑有问题,原先的代码检测的是 VibrationEffect 被写到 parcel 里所需要的大小,补丁改成了在写 xml 的时候跳过太长的结果。

CVE-2026-0016 ID High
系统重置 CREDENTIAL_SERVICE_PRIMARY 的时候错误用了自己的 user id,扫描并移除无效服务的时候也没检查 user id

CVE-2026-0036 ID High
窗口管理的问题,给错类型了,看得不是很明白,描述是 tapjacking,把提交信息复制过来看看

1
2
3
4
5
6
7
8
9
10
11
12
13
Start a new transition to ignore split-enter from a malformed transition

- If two tasks are started in immediately one after the other in order
with the latter being an adjacent launch, the launch of the two tasks
can end up in the same transition but the transition request will
report the first task launch as the trigger task. As a result,
StageCoordinator will not be resolved as the handler for the
transition and the enter transition not play correctly (falling
through the default transition handler which only shows the adjacent
task without being in split).

If we detect this rare edge case, we instead restore the adjacent task
to the TaskDisplayArea instead of treating it as an adjacent launch.

CVE-2026-0056 ID High
校验 ResStringPool_header.styleCount 避免越界读

CVE-2026-28586 ID High
在 AppOpsService startOp 和 noteOp 里检查 app 是否因为被 suspend 而不能执行这些操作

CVE-2025-32348 DoS High
现在不会因为 app 有 PIP 窗口 允许 BAL。这类型给的也太离谱了点

CVE-2026-0018 DoS High
过滤掉无效的无障碍服务磁贴,不是很清楚会发生什么

CVE-2026-0069 DoS High
我报的垃圾洞,没啥看的价值

CVE-2026-0070 DoS High
禁止隐藏 settings、settings provider 和 nfc 服务,即使在 work profile 里隐藏这些 app 也可能导致开机失败

CVE-2026-28578 DoS High
设置 work profile 的 caller id、contacts access 和 credential manager 政策的时候检查包名长度

System

CVE-2026-0043 EoP Critical
CVE-2026-0039 DoS Critical
CVE-2026-0040 DoS Critical
CVE-2026-0041 DoS Critical
CVE-2026-0042 DoS Critical
CVE-2026-0044 DoS Critical
CVE-2026-0051 DoS Critical
CVE-2026-0052 DoS Critical
CVE-2026-0080 DoS Critical
CVE-2026-0067 DoS High
CVE-2026-0079 DoS High
dng_sdk 中的多个整数溢出

CVE-2026-0097 EoP Critical
蓝牙 LE 安全连接中的用户交互绕过问题

CVE-2026-21352 EoP Critical
CVE-2026-21353 EoP Critical
升级 dng_sdk 到 1.7.1 2471

CVE-2025-64505 DoS Critical
libpng 1.6.51 之前的越界读

CVE-2026-0059 RCE High
蓝牙 sdp discovery 的越界写,校验剩余数据大小

CVE-2025-26418 EoP High
车机 CarDevicePolicyService setUserDisclaimerAcknowledged API 添加权限检查,保证添加账号的弹窗不被跳过

CVE-2025-48581 EoP High
apexd 中的业务 bug,会导致安全更新无法安装

CVE-2025-48612 EoP High
去年放过一遍的洞,因为补丁有问题被撤回了,去25年分析看吧

CVE-2026-0045 EoP High
蓝牙的问题,没太看明白

1
2
3
4
5
6
7
8
9
10
11
RFCOMM MUX connection request must not start bonding

Outgoing connection requests for secure sockets adds the bonding
security requirements for RFCOMM MUX. This security requirement is reset
only when an outgoing insecure socket connection is requested. This
means that all subsequent incoming connection requests for RFCOMM MUX
also enforce the bonding requirement. So incoming RFCOMM connection
leads to initiating bonding.

This is a backport of ag/36338174 required for a security fix. Also
includes flag removal for upgrade_temp_bonding_on_auth_req.

CVE-2026-0075 EoP High
ContactsProvider2 中通过畸形查询+解析 SQLite 抛出的异常信息实现的侧信道攻击,补丁把异常信息给 strip 了

CVE-2026-0086 EoP High
调用者为 null 时主动失败,避免检查 null 是否为 role holder。补丁:
https://cs.android.com/android/_/android/platform/packages/apps/Settings/+/f0922db8cc4c1cb515c8a2a580993aa061481f65

CVE-2026-0088 EoP High
CertInstaller 里的长应用名攻击,使用 loadSafeLabel 代替 loadLabel

CVE-2026-0093 EoP High
RequestManageCredentials 里的长应用名攻击

CVE-2026-0094 EoP High
KeyChainActivity 里的长应用名攻击

CVE-2026-0095 EoP High
蓝牙 l2cap 里的整数溢出

CVE-2026-0096 EoP High
ForgetDeviceDialogFragment 里的长应用名攻击

CVE-2026-0098 EoP High
很久之前报的垃圾洞,DocumentsUI 里只要调用者是系统预装 app (有 FLAG_SYSTEM 或者 FLAG_UPDATED_SYSTEM_APP 标记)就允许它自定义在授权弹窗里显示出来的应用名,现在改成必须和系统签名相同了

CVE-2026-0099 EoP High
nfc 服务绑定 HostApduService 的时候收到 onNullBinding 或者 onBindingDied 要解绑服务

CVE-2026-28574 EoP High
nfc 服务的 race condition,导致服务不被解绑 -> BAL

CVE-2025-48600 ID High
IntentResolver 里检查提供的 icon uri。官方公告放错了补丁,是这个才对:
https://android.googlesource.com/platform/packages/modules/IntentResolver/+/bbe2dc3fb85fac9053b427b6d3c4af3506e0d9b4

CVE-2025-48616 ID High
SystemUI 检查是否在 lockdown 模式时使用 KeyguardUpdateMonitor 代替 LockPatternUtils

CVE-2026-0050 ID High
有与之前绑定过的蓝牙设备同地址的设备尝试重新绑定时撤销权限,因为设备地址可以伪造,同地址并不代表一定是同一个设备

CVE-2025-48648 DoS High
我报的一个没啥用但是比较有意思的 DoS,sdk sandbox 可以以不同的 uid 运行,而 NotificationManagerService 做数据大小限制是对 uid 做的,所以只要有多个 app 调用同一个 sdk 就能绕过限制造成 dos
补丁写得比较让人一头雾水,把 PackageManagerInternal.isSameApp 改成 UserHandle.isSameApp,这是因为前者允许 sdk sandbox 而后者不允许,所以修改检查就能直接禁止 sdk sandbox 调用通知服务

CVE-2026-0060 DoS High
在开发者选项里启用 ANGLE 的时候显示警告提醒用户备份数据,要不然把设备搞砖了数据就丢了

CVE-2026-0074 DoS High
Launcher 解码图像时缩小图像尺寸以降低内存占用

CVE-2026-0085 DoS High
ContactsProvider 限制大小时把大小写不匹配的 key 也纳入进去

2026-06-05

Pixel Kernel Components / Video Processing Unit

CVE-2026-0125 EoP High
https://project-zero.issues.chromium.org/issues/492567103

2026-05-01

CVE-2026-0073 RCE Critical
adbd 中的校验逻辑错误,需要开发者选项&无线调试打开且至少配对过一个密钥。很少见的不是内存问题的 RCE。
https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/

2026-04-01

Framework

CVE-2026-0049 DoS Critical
DNG_SDK dng_opcode_MapTable::ProcessArea() 中的整数溢出问题。

2026-03-01

在野利用漏洞:CVE-2026-21385

Framework

CVE-2026-0047 EoP Critical
只影响 16-qpr2 的漏洞。截至发稿,漏洞补丁未公开。漏洞描述:

In dumpBitmapsProto of ActivityManagerService.java, there is a possible way for an app to access private information due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

根据已经公开的 16 QPR2 源码,可以很明显地看出来提交 https://cs.android.com/android/_/android/platform/frameworks/base/+/0ebd869c069fb58671b947955be1e67241783d73 在 activity manager 引入了 dumpBitmapsProto 这个 aidl 调用,可以获得系统里面正在运行的所有 java 进程里的所有 bitmap 数据而没有任何权限保护,很明显的漏洞。

补丁链接:
https://github.com/GrapheneOS/platform_frameworks_base/commit/0a02ed34a8bfafe9022b7009145b9ad962c9a64f

CVE-2025-32313 EoP High
又放了个无法访问的链接。。。
手动大法,获得这两个:
https://android.googlesource.com/platform/frameworks/base/+/fd4045126ff01cec3d65c053a0c2c01dc231a0f5
https://android.googlesource.com/platform/frameworks/native/+/611b730bade54a0a79dbcc3087d9393086e6dbdf
也就是 Parcel.setDataPosition() 设置的 position 大于 Parcel.dataSize() 时不会正确增长 buffer,造成越界写。通过反序列化 NotificationHistory 对象时使用畸形数据触发。
漏洞描述又是 UsageEvents 里的 OOB write,不知道发什么神经

CVE-2025-48544 EoP High
去年 9 月放过,又放了一遍,懒得重新分析了,看之前的吧

CVE-2025-48567 EoP High
之前 CVE-2024-43093 的后续,MediaProvider 里使用正则过滤敏感路径,需要去除掉路径中的可忽略代码点

CVE-2025-48568 EoP High
https://android.googlesource.com/platform/frameworks/base/+/d8c3d450f77f77232a89ac37c9b9b266e28c0202
切换用户过程中的 race condition,导致锁屏绕过。这个问题我有时候会碰到,不知道修没修好。

CVE-2025-48574 EoP High
WindowManagerService 内对 PRIVATE_FLAG_INTERCEPT_GLOBAL_DRAG_AND_DROP 的权限检查损坏,在 Binder.clearCallingIdentity() 之后调用了 ActivityTaskManagerService.enforceTaskPermission() 检查权限,里面用的是 checkCallingPermission(),而它依赖 Binder.getCallingUid() 的结果,实际上不会起到任何作用,因此可以拦截用户 drag and drop 传递的数据。
这个漏洞我在 2025 年 7 月 29 日报过,duplicate,看 issue id 可能也就差几天的时间,可惜了

CVE-2025-48578 EoP High
MediaProvider 收到畸形 URI (authority 不正确,或者无法把 id 解析成数字)的时候恢复 binder calling identity 再继续执行。

CVE-2025-48579 EoP High
补丁链接跟 CVE-2025-48578 是一样的。

CVE-2025-48582 EoP High
此漏洞由我发现并报告。
MediaProvider 请求权限的 PermissionActivity 内使用了不安全的 getCallingPackage() 获取调用者身份,可以被伪造导致权限绕过。补丁改成在 createRequest() 的时候记录 calling uid。

CVE-2025-48605 EoP High
SystemUI 显示锁屏的时候移除队列里已有的隐藏锁屏消息,防止残留的请求意外 dismiss 掉锁屏

CVE-2025-48619 EoP High
ContentProvider 被要求打开文件的时候,如果 mode 里没有 w,这个时候 framework 只会检查读权限,过滤掉 truncate bit 和 append bit 避免只有读权限的调用者裁剪文件。

CVE-2025-48634 EoP High
WindowManagerService relayoutWindow 的过程中没有对 private flags 做权限检查,任何 app 都能使用 PRIVATE_FLAG_TRUSTED_OVERLAY PRIVATE_FLAG_INTERCEPT_GLOBAL_DRAG_AND_DROP 等敏感 flag。

CVE-2025-48635 EoP High
此漏洞由我发现并报告。
补丁:https://android.googlesource.com/platform/frameworks/base/+/36e65fce2d5119ad1d62b4696c003f93df649e52
问题跟 CVE-2025-0098 基本是一样的,当时只修了 android 15,但是有问题的代码其实在 android 14 就存在了,然后我又报了一个。

CVE-2025-48645 EoP High
加载 device admin info 的 description 时 catch OOM,避免超大字符串导致崩溃

CVE-2025-48646 EoP High
https://konata.github.io/posts/identity-squashing/

CVE-2025-48654 EoP High
系统开机的时候移除所有已被 revoke 的 companion device associations

CVE-2026-0007 EoP High
往 parcel 写入 WindowInfo.name 的时候截断超长字符串,这个涉及到我之前提出的一种新攻击手段,后续会发文章介绍

CVE-2026-0010 EoP High
drmserver 中的越界写/栈上缓冲区溢出

CVE-2026-0011 EoP High
修复 shared user id 的系统 app 卸载更新然后重新启用时没有重用现有的状态会被重新分配一个新的 uid 的 bug。

CVE-2026-0013 EoP High
DocumentsUI PickActivity 重用来源 intent 启动 activity 之前先清掉 selector,避免用 DocumentsUI 的权限启动任意 activity

CVE-2026-0020 EoP High
解析权限的时候去除名字里的头尾空格,看描述是能绕过授权弹窗

CVE-2026-0023 EoP High
安装 app 时忽略外部传来的 INSTALL_FROM_MANAGED_USER_OR_PROFILE 标志

CVE-2026-0026 EoP High
补丁:
https://android.googlesource.com/platform/frameworks/base/+/0ead58f69f5de82b00406316b333366d556239f1
https://android.googlesource.com/platform/frameworks/base/+/528a87e90ff9354581d54fd37fbe9f95cccbcdb1
之前的 CVE-2023-20971,不知道为啥重新给了一个 CVE,终于发现之前给的 CVE 不对了吗?

CVE-2026-0034 EoP High
限制最多只能激活 100 个 notification listener service / condition provider service,避免序列化太长的字符串导致异常

CVE-2025-48630 ID High
绘制模糊区域时使用边界图层进行裁剪,防止超出图层边界。看起来是之前 CVE-2025-48561 (Pixnapping) 的后续,https://www.pixnapping.com/

CVE-2026-0012 ID High
官方公告放少了一个补丁所以看起来怪怪的,应该需要以下两个补丁才对:
https://android.googlesource.com/platform/frameworks/base/+/f275f865d49559a6bb3ef9cecf0ab1dd7a7a0bc3
https://android.googlesource.com/platform/frameworks/base/+/e93d4b015c283e55cb08d68a499aab41f03e1272
所以是动画导致的 contact name leak?

CVE-2026-0025 ID High
Notification 从 extras 里还原 EXTRA_MESSAGES 和 EXTRA_HISTORIC_MESSAGES 没有类型限制,可以往里添加一个 ParceledListSlice,因为 ParceledListSlice 反序列化时需要调用回对端提供的 binder,在 system server 去 visit uri 的时候 app 可以返回畸形数据,让 system server 反序列化 messages 时 ParceledListSlice 抛出异常导致整项都反序列化失败,然后 defuse 返回 null,因此被 visit uri 跳过;在 SystemUI 去读的时候就返回可被解析的数据,让 messages 可以被 SystemUI 正常读取和渲染。补丁就是限制了 EXTRA_MESSAGES 和 EXTRA_HISTORIC_MESSAGES 数组的每一项都必须是 bundle。

CVE-2025-48644 DoS High
解析输入法 metadata 的时候限制里面 string 的大小,防止超过 binder 传输大小。

CVE-2026-0014 DoS High
此漏洞由我发现并报告。
AppOpsService 内信任一切安装在 system image 上的 app 提供的 AttributionTag,这个检查可以被 SDK Sandbox 绕过,跟 CVE-2025-48524 CVE-2025-48545 是类似的。

CVE-2026-0015 DoS High
AppOpsService 内忽略不可信 proxy 提供的无效 proxied attribution tag,之前的代码里如果提供的 proxied attribution tag 在被代理的 package 里找不到但是 proxy 里能找到还是会认为它有效,现在即使 proxy 里能找到,如果请求来自不可信 proxy 也会忽略掉它。

System

CVE-2026-0006 RCE Critical
libopenapv 中的越界读写/堆上缓冲区溢出,把它更新到 v0.2.0.0。只影响 16

CVE-2025-48631 DoS Critical
去年 12 月的 CVE-2025-48631 重新放一遍,当时 16 QPR2 没修好

CVE-2025-48577 EoP High
SystemUI 切换用户时如果收到生物认证或者解除锁屏请求,可能会因为 race condition 导致发生在错误的用户上。添加用户 id 验证以避免这些情况。

CVE-2025-48602 EoP High
用户切换的时候取消还在队列里的播放锁屏退出动画的请求。

CVE-2025-48641 EoP High
nfc 中多线程访问造成的 UAF,需要加锁

CVE-2025-48650 EoP High
MmsProvider/SmsProvider/MmsSmsProvider 中的 SQL 注入,加了个括号平衡的检查

CVE-2025-48653 EoP High
合并同一个 shared user id 中所有 package 请求的所有权限。如果 Package A 属于 UID U,A 没有请求某个权限 P 但是它的 UID U 有这个权限(比如 U 里的其他 app 请求了它),因为权限检查是基于 uid 的,A 实际上也可以使用这个权限,所以 PermissionController 在查看 A 的权限使用记录的时候也必须包含它使用 P 的记录。

CVE-2026-0017 EoP High
高版本(16+)的“使用生物认证解锁”使用的 Settings.Secure 项和低版本的不同,旧版本更新到 16+ 之后系统只会去读新的 Settings.Secure 项的值,只能获得默认的 ON,即使更新系统之前把这项功能关掉了,更新之后还是可以生物认证解锁手机。添加迁移逻辑避免这个问题。

CVE-2026-0021 EoP High
Settings 如果是 2 pane (大屏设备),AppInfoBase 检查 calling package 的跨用户权限而非 calling uid 的权限,因为 multi pane 的实现需要 Settings 用自己的权限去重新启动 activity,这个过程会导致 calling uid 变成 Settings 自己的,具体见 https://cs.android.com/android/platform/superproject/+/android-16.0.0_r1:packages/apps/Settings/src/com/android/settings/homepage/SettingsHomepageActivity.java;l=678
这个问题我之前看出来了,本来打算有空的时候实验然后提交,结果就忘了。。。这里经过最开始我报的 CVE-2024-43088 后面 CVE-2025-22428,兜兜转转最后又回到原点。不知道以后还有没有

CVE-2026-0035 EoP High
MediaProvider 不允许获得不存在的文件的权限,避免悬空攻击

CVE-2024-43766 ID High
蓝牙里的未加密通信?

CVE-2025-48642 ID High
使用 dc cvac 指令代替 dc cvau,保证数据写入到主存。https://zhuanlan.zhihu.com/p/718112749

CVE-2025-64783 ID High
更新 DNG SDK 到 1.7.1 2410

CVE-2025-64784 ID High
和上面的一样

CVE-2025-64893 ID High
和上面的一样

CVE-2026-0005 ID High
SystemUI crash 重启后重新进入 app pinning 模式。类型给错了吧?应该给 EoP

CVE-2026-0024 ID High
使用 file picker 选择媒体文件的时候检查请求 app 有没有权限从里面读取位置,如果没权限应该去除掉位置信息(比如 EXIF 里可能包含位置)

CVE-2025-48585 DoS High
ProfilingService 里保证传入的包名属于 calling uid,只影响 16

CVE-2025-48587 DoS High
ProfilingService 添加 trigger 的时候校验 trigger 的类型确保是合法的,只影响 16

CVE-2025-48609 DoS High
MmsProvider 里的路径穿越,以 phone 的权限删除任意文件造成电话/短信/彩信功能异常

2026-03-05

Pixel

CVE-2026-0112 EoP High
https://project-zero.issues.chromium.org/issues/463672550

CVE-2026-0121 ID High
https://project-zero.issues.chromium.org/issues/465824679

2026-02-01

木大木大,全部木大

2026-02-05

Pixel

CVE-2026-0106 EoP High
https://project-zero.issues.chromium.org/issues/463438263
https://projectzero.google/2026/05/pixel-10-exploit.html

2026-01-05

Dolby

CVE-2025-54957 RCE Critical
https://project-zero.issues.chromium.org/issues/428075495
https://projectzero.google/2026/01/pixel-0-click-part-1.html