{"id":"ASB-A-281044385","details":"In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-281044385","CVE-2024-43084"],"modified":"2026-05-22T15:55:21.353668239Z","published":"2024-11-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2024-11-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/base/+/50eec20b570cd4cbbe8c5971af4c9dda3ddcb858"}],"affected":[{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15-next:0"},{"fixed":"15-next:2024-11-01"}]}],"versions":["15-next"],"ecosystem_specific":{"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/base/+/57bf60dd7b6a0a0e9785231f8ec25a458fedde64","https://android.googlesource.com/platform/frameworks/base/+/47fa2f79584b0a4e9ca7e9c6b237c4e5cf699032"],"vanir_signatures":[{"source":"https://android.googlesource.com/platform/frameworks/base/+/57bf60dd7b6a0a0e9785231f8ec25a458fedde64","signature_version":"v1","id":"ASB-A-281044385-832e8fce","deprecated":false,"target":{"file":"core/java/android/widget/RemoteViews.java"},"digest":{"threshold":0.9,"line_hashes":["10510999966334574279305722242451318199","45624935327614318953256630095580261923","88862101754165718251039929288440973010","123442478213385419831478048965200226762","261571390405565706709003200902133125804","45883897862656844072827701537777195070","142764219807960318275023873616153889276","155373235451303780094325786996518966673","49981588967733474517399634290453951563","83286379831050784995635899275405895041","243555200852200659624259429292278405497","155373235451303780094325786996518966673","49981588967733474517399634290453951563","184378576880802386689416999093283739996","191806936659674396850792655262886060745","21235937052953042572597888800073948978","200180594152380276820622654550619540821","29079217341050940120791020350458989067","81595622362258368310746865327607710615","302086928097423432627172955140172345953","173993705994644571187001930534900680128","81713959684661101519637763887157616690","219374834455587785019446754860677867943","124672837057353313624121635866941804072","54451855161250744561465910213750156585","93626569860004836606333716824471718244","149247579473422910260981314518031220889","27219370413290196648737613963397520106","233859046065629953084836555122924572024","319564703865883751452108161908231449715","75407180318704451699303769443305508093","161647537139600399971971420418828399569","42215653947126611667948844128824813674","162365430782717823755100250245402003271","225668494625327505211209031266487151798","160613521035711799537827983944293222081","200322272169322909612143317388256242218","222512300424861850237015065106727888205","52959140454601314760806148885371656096"]},"signature_type":"Line"},{"deprecated":false,"target":{"file":"core/java/android/app/Person.java","function":"visitUris"},"source":"https://android.googlesource.com/platform/frameworks/base/+/47fa2f79584b0a4e9ca7e9c6b237c4e5cf699032","signature_version":"v1","id":"ASB-A-281044385-943db91a","digest":{"function_hash":"288860386835197189624262581952663062056","length":80},"signature_type":"Function"},{"id":"ASB-A-281044385-e62b1f70","deprecated":false,"target":{"file":"core/java/android/app/Person.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/47fa2f79584b0a4e9ca7e9c6b237c4e5cf699032","signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["81780510925217913499770296184564214094","139543985378760233612091164945055767821","116210352605243371856843879751749052626","214019929480860862798213677602168558104"]},"signature_type":"Line"}],"types":["ID"],"spl":"2024-11-01"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-281044385.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2024-11-01"}]}],"versions":["12"],"ecosystem_specific":{"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df"],"spl":"2024-11-01","types":["ID"],"vanir_signatures":[{"deprecated":false,"target":{"file":"core/java/android/app/Notification.java","function":"visitUris"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","id":"ASB-A-281044385-35a44618","digest":{"function_hash":"226261594227612019666750231890952133595","length":2793},"signature_type":"Function"},{"signature_version":"v1","id":"ASB-A-281044385-8227cd73","deprecated":false,"target":{"file":"core/java/android/app/Person.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","digest":{"threshold":0.9,"line_hashes":["263836019758200982776463401040620721465","247546774655072607342278836609046467938","60521504124628552930342395875500525768","282050567308648304240900420240262779473","2718882073265626309970603630629726759","158170123605905798769055961164006144147","155955290926441644593181321547220907309"]},"signature_type":"Line"},{"signature_version":"v1","id":"ASB-A-281044385-99563c77","deprecated":false,"target":{"file":"core/java/android/widget/RemoteViews.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","digest":{"threshold":0.9,"line_hashes":["166581626050355692230681923528270581926","127862451652953392467269614167688254154","70747653424863626440410349412645158303","78607243364527635630614543284193929158","336772395560394250562884253332587950912","39075794854455879723216048164179215899","278605636933568622048356062034643752185","160613521035711799537827983944293222081","200322272169322909612143317388256242218","13717106412723118880393556138652855111","144967073499775357945133104004113875671"]},"signature_type":"Line"},{"signature_version":"v1","id":"ASB-A-281044385-ad599ba7","deprecated":false,"target":{"file":"core/java/android/app/Notification.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","digest":{"threshold":0.9,"line_hashes":["209530810119055766998990867496632062624","781225146328105575814677055182072393","201520778652802430645411465180549161940","137848556094638840852305046988100462751","197585125163988185987062498860316791841","293871498699140096628809383344655540256","7545405675158435223214904835203408928","253958536906314139404070984156214930226","18077601078121824348472074983136224998","174773538391543390547072899090801225263","111010618835311138444835914450006549286","69786244909812671898944025900688175323","216588021725256539435549669659028307145","251798009144440653857833564898080930463","204285425078065425977243654658516906718","48970497240407572097776512813103235977","94526450022358076459367478520942778064","208846296421393991542105520785753736042","150974507026362302543711859426234228469","337979760446688541559158736326994342903","19432528061896917112512453997124569067","251798009144440653857833564898080930463","204285425078065425977243654658516906718","48970497240407572097776512813103235977","94526450022358076459367478520942778064","183671867846423336259288113830564499130","158581719279055811332391153585680921660","149572172347206097383450124856241791941","216047209128885008134994698672488946183","230604067347090329615129250887209897007","92197796532099970008722051383325345004","45236288524958094379757701234169193903","29984996119810792357635301028200065016"]},"signature_type":"Line"}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-281044385.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12L:0"},{"fixed":"12L:2024-11-01"}]}],"versions":["12L"],"ecosystem_specific":{"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df"],"spl":"2024-11-01","types":["ID"],"vanir_signatures":[{"target":{"file":"core/java/android/app/Notification.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","id":"ASB-A-281044385-4c703e42","deprecated":false,"digest":{"threshold":0.9,"line_hashes":["209530810119055766998990867496632062624","781225146328105575814677055182072393","201520778652802430645411465180549161940","137848556094638840852305046988100462751","197585125163988185987062498860316791841","293871498699140096628809383344655540256","7545405675158435223214904835203408928","253958536906314139404070984156214930226","18077601078121824348472074983136224998","174773538391543390547072899090801225263","111010618835311138444835914450006549286","69786244909812671898944025900688175323","216588021725256539435549669659028307145","251798009144440653857833564898080930463","204285425078065425977243654658516906718","48970497240407572097776512813103235977","94526450022358076459367478520942778064","208846296421393991542105520785753736042","150974507026362302543711859426234228469","337979760446688541559158736326994342903","19432528061896917112512453997124569067","251798009144440653857833564898080930463","204285425078065425977243654658516906718","48970497240407572097776512813103235977","94526450022358076459367478520942778064","183671867846423336259288113830564499130","158581719279055811332391153585680921660","149572172347206097383450124856241791941","216047209128885008134994698672488946183","230604067347090329615129250887209897007","92197796532099970008722051383325345004","45236288524958094379757701234169193903","29984996119810792357635301028200065016"]},"signature_type":"Line"},{"deprecated":false,"target":{"file":"core/java/android/app/Person.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","id":"ASB-A-281044385-8a9a3ba0","digest":{"threshold":0.9,"line_hashes":["263836019758200982776463401040620721465","247546774655072607342278836609046467938","60521504124628552930342395875500525768","282050567308648304240900420240262779473","2718882073265626309970603630629726759","158170123605905798769055961164006144147","155955290926441644593181321547220907309"]},"signature_type":"Line"},{"deprecated":false,"target":{"file":"core/java/android/app/Notification.java","function":"visitUris"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","id":"ASB-A-281044385-94461039","digest":{"length":2793,"function_hash":"226261594227612019666750231890952133595"},"signature_type":"Function"},{"deprecated":false,"target":{"file":"core/java/android/widget/RemoteViews.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","id":"ASB-A-281044385-a959b1f6","digest":{"threshold":0.9,"line_hashes":["166581626050355692230681923528270581926","127862451652953392467269614167688254154","70747653424863626440410349412645158303","78607243364527635630614543284193929158","336772395560394250562884253332587950912","39075794854455879723216048164179215899","278605636933568622048356062034643752185","160613521035711799537827983944293222081","200322272169322909612143317388256242218","13717106412723118880393556138652855111","144967073499775357945133104004113875671"]},"signature_type":"Line"}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-281044385.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2024-11-01"}]}],"versions":["13"],"ecosystem_specific":{"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df"],"spl":"2024-11-01","types":["ID"],"vanir_signatures":[{"id":"ASB-A-281044385-40d2e949","deprecated":false,"target":{"file":"core/java/android/app/Notification.java","function":"visitUris"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","digest":{"length":2793,"function_hash":"226261594227612019666750231890952133595"},"signature_type":"Function"},{"id":"ASB-A-281044385-45b9f910","deprecated":false,"target":{"file":"core/java/android/app/Person.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","digest":{"threshold":0.9,"line_hashes":["263836019758200982776463401040620721465","247546774655072607342278836609046467938","60521504124628552930342395875500525768","282050567308648304240900420240262779473","2718882073265626309970603630629726759","158170123605905798769055961164006144147","155955290926441644593181321547220907309"]},"signature_type":"Line"},{"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","id":"ASB-A-281044385-466d13b9","deprecated":false,"target":{"file":"core/java/android/app/Notification.java"},"digest":{"threshold":0.9,"line_hashes":["209530810119055766998990867496632062624","781225146328105575814677055182072393","201520778652802430645411465180549161940","137848556094638840852305046988100462751","197585125163988185987062498860316791841","293871498699140096628809383344655540256","7545405675158435223214904835203408928","253958536906314139404070984156214930226","18077601078121824348472074983136224998","174773538391543390547072899090801225263","111010618835311138444835914450006549286","69786244909812671898944025900688175323","216588021725256539435549669659028307145","251798009144440653857833564898080930463","204285425078065425977243654658516906718","48970497240407572097776512813103235977","94526450022358076459367478520942778064","208846296421393991542105520785753736042","150974507026362302543711859426234228469","337979760446688541559158736326994342903","19432528061896917112512453997124569067","251798009144440653857833564898080930463","204285425078065425977243654658516906718","48970497240407572097776512813103235977","94526450022358076459367478520942778064","183671867846423336259288113830564499130","158581719279055811332391153585680921660","149572172347206097383450124856241791941","216047209128885008134994698672488946183","230604067347090329615129250887209897007","92197796532099970008722051383325345004","45236288524958094379757701234169193903","29984996119810792357635301028200065016"]},"signature_type":"Line"},{"target":{"file":"core/java/android/widget/RemoteViews.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","id":"ASB-A-281044385-7fe3963e","deprecated":false,"digest":{"threshold":0.9,"line_hashes":["166581626050355692230681923528270581926","127862451652953392467269614167688254154","70747653424863626440410349412645158303","78607243364527635630614543284193929158","336772395560394250562884253332587950912","39075794854455879723216048164179215899","278605636933568622048356062034643752185","160613521035711799537827983944293222081","200322272169322909612143317388256242218","13717106412723118880393556138652855111","144967073499775357945133104004113875671"]},"signature_type":"Line"}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-281044385.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14:0"},{"fixed":"14:2024-11-01"}]}],"versions":["14"],"ecosystem_specific":{"severity":"High","fixes":["https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df"],"spl":"2024-11-01","types":["ID"],"vanir_signatures":[{"deprecated":false,"target":{"file":"core/java/android/app/Person.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","id":"ASB-A-281044385-0c1f61d5","digest":{"threshold":0.9,"line_hashes":["263836019758200982776463401040620721465","247546774655072607342278836609046467938","60521504124628552930342395875500525768","282050567308648304240900420240262779473","2718882073265626309970603630629726759","158170123605905798769055961164006144147","155955290926441644593181321547220907309"]},"signature_type":"Line"},{"signature_version":"v1","id":"ASB-A-281044385-4b3ba66e","deprecated":false,"target":{"file":"core/java/android/app/Notification.java","function":"visitUris"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","digest":{"function_hash":"226261594227612019666750231890952133595","length":2793},"signature_type":"Function"},{"signature_version":"v1","id":"ASB-A-281044385-a06d57e8","deprecated":false,"target":{"file":"core/java/android/app/Notification.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","digest":{"threshold":0.9,"line_hashes":["209530810119055766998990867496632062624","781225146328105575814677055182072393","201520778652802430645411465180549161940","137848556094638840852305046988100462751","197585125163988185987062498860316791841","293871498699140096628809383344655540256","7545405675158435223214904835203408928","253958536906314139404070984156214930226","18077601078121824348472074983136224998","174773538391543390547072899090801225263","111010618835311138444835914450006549286","69786244909812671898944025900688175323","216588021725256539435549669659028307145","251798009144440653857833564898080930463","204285425078065425977243654658516906718","48970497240407572097776512813103235977","94526450022358076459367478520942778064","208846296421393991542105520785753736042","150974507026362302543711859426234228469","337979760446688541559158736326994342903","19432528061896917112512453997124569067","251798009144440653857833564898080930463","204285425078065425977243654658516906718","48970497240407572097776512813103235977","94526450022358076459367478520942778064","183671867846423336259288113830564499130","158581719279055811332391153585680921660","149572172347206097383450124856241791941","216047209128885008134994698672488946183","230604067347090329615129250887209897007","92197796532099970008722051383325345004","45236288524958094379757701234169193903","29984996119810792357635301028200065016"]},"signature_type":"Line"},{"deprecated":false,"target":{"file":"core/java/android/widget/RemoteViews.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/7c373d6c6d089c42502a70c6abc457606cc670df","signature_version":"v1","id":"ASB-A-281044385-af0184f7","digest":{"threshold":0.9,"line_hashes":["166581626050355692230681923528270581926","127862451652953392467269614167688254154","70747653424863626440410349412645158303","78607243364527635630614543284193929158","336772395560394250562884253332587950912","39075794854455879723216048164179215899","278605636933568622048356062034643752185","160613521035711799537827983944293222081","200322272169322909612143317388256242218","13717106412723118880393556138652855111","144967073499775357945133104004113875671"]},"signature_type":"Line"}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-281044385.json"}}],"schema_version":"1.7.5"}