{"id":"ASB-A-353680402","details":"In assertSafeToStartCustomActivity of AppRestrictionsFragment.java , there is a possible way to exploit a parcel mismatch resulting in a launch anywhere vulnerability due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-353680402","CVE-2025-48535"],"modified":"2026-04-10T16:16:18.068628Z","published":"2025-09-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2025-09-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/packages/apps/Settings/+/25ed933c4cf5acb7a15c146332f9586f3dd1abe0"}],"affected":[{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16-next:0"},{"fixed":"16-next:2025-09-01"}]}],"versions":["16-next"],"ecosystem_specific":{"spl":"2025-09-01","types":["EoP"],"severity":"High","vanir_signatures":[{"digest":{"length":583,"function_hash":"167051775218518309602972445688464531447"},"deprecated":false,"signature_type":"Function","target":{"function":"assertSafeToStartCustomActivity","file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/b7240e2f0c50455a1c8f3ae1fc4f27d55b86e89b","id":"ASB-A-353680402-1a5f3406"},{"digest":{"line_hashes":["87249741624904178570740848043246456225","322900107720807731356549153451401585236","30641909703164034095131522789235472829","312449678066938024485074749804097670041","204461751170142905684839284015484469701","275251800527781872931916296749898367687","276736092446101932266423162397011781416","220607371548842682738531909079559250648","193851804838495652505114225811346447401","335330703028102328901877311581203144736"],"threshold":0.9},"deprecated":false,"signature_type":"Line","target":{"file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/b7240e2f0c50455a1c8f3ae1fc4f27d55b86e89b","id":"ASB-A-353680402-97e00931"}],"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/b7240e2f0c50455a1c8f3ae1fc4f27d55b86e89b"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-353680402.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15:0"},{"fixed":"15:2025-09-01"}]}],"versions":["15"],"ecosystem_specific":{"spl":"2025-09-01","types":["EoP"],"severity":"High","vanir_signatures":[{"digest":{"line_hashes":["87249741624904178570740848043246456225","322900107720807731356549153451401585236","30641909703164034095131522789235472829","312449678066938024485074749804097670041","204461751170142905684839284015484469701","275251800527781872931916296749898367687","276736092446101932266423162397011781416","220607371548842682738531909079559250648","193851804838495652505114225811346447401","335330703028102328901877311581203144736"],"threshold":0.9},"deprecated":false,"signature_type":"Line","target":{"file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/9a2ddc6aab7950ab3c527321d4eab8e578097936","id":"ASB-A-353680402-8a2b1021"},{"digest":{"length":583,"function_hash":"167051775218518309602972445688464531447"},"deprecated":false,"signature_type":"Function","target":{"function":"assertSafeToStartCustomActivity","file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/9a2ddc6aab7950ab3c527321d4eab8e578097936","id":"ASB-A-353680402-8d0f6de5"}],"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/9a2ddc6aab7950ab3c527321d4eab8e578097936"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-353680402.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"16:0"},{"fixed":"16:2025-09-01"}]}],"versions":["16"],"ecosystem_specific":{"spl":"2025-09-01","types":["EoP"],"severity":"High","vanir_signatures":[{"digest":{"length":583,"function_hash":"167051775218518309602972445688464531447"},"deprecated":false,"signature_type":"Function","target":{"function":"assertSafeToStartCustomActivity","file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/d8166274a030372f9b1184137fceef9d4dac83e1","id":"ASB-A-353680402-1ad0895b"},{"digest":{"line_hashes":["87249741624904178570740848043246456225","322900107720807731356549153451401585236","30641909703164034095131522789235472829","312449678066938024485074749804097670041","204461751170142905684839284015484469701","275251800527781872931916296749898367687","276736092446101932266423162397011781416","220607371548842682738531909079559250648","193851804838495652505114225811346447401","335330703028102328901877311581203144736"],"threshold":0.9},"deprecated":false,"signature_type":"Line","target":{"file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/d8166274a030372f9b1184137fceef9d4dac83e1","id":"ASB-A-353680402-bcccbde6"}],"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/d8166274a030372f9b1184137fceef9d4dac83e1"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-353680402.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2025-09-01"}]}],"versions":["13"],"ecosystem_specific":{"spl":"2025-09-01","types":["EoP"],"severity":"High","vanir_signatures":[{"digest":{"line_hashes":["87249741624904178570740848043246456225","322900107720807731356549153451401585236","30641909703164034095131522789235472829","312449678066938024485074749804097670041","204461751170142905684839284015484469701","275251800527781872931916296749898367687","276736092446101932266423162397011781416","220607371548842682738531909079559250648","193851804838495652505114225811346447401","335330703028102328901877311581203144736"],"threshold":0.9},"deprecated":false,"signature_type":"Line","target":{"file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/4dddd8cbc6757a06b92acf7f77f4bbecb363ed6c","id":"ASB-A-353680402-b0306cd4"},{"digest":{"length":583,"function_hash":"167051775218518309602972445688464531447"},"deprecated":false,"signature_type":"Function","target":{"function":"assertSafeToStartCustomActivity","file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/4dddd8cbc6757a06b92acf7f77f4bbecb363ed6c","id":"ASB-A-353680402-d478113e"}],"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/4dddd8cbc6757a06b92acf7f77f4bbecb363ed6c"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-353680402.json"}},{"package":{"name":"platform/packages/apps/Settings","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14:0"},{"fixed":"14:2025-09-01"}]}],"versions":["14"],"ecosystem_specific":{"spl":"2025-09-01","types":["EoP"],"severity":"High","vanir_signatures":[{"digest":{"line_hashes":["87249741624904178570740848043246456225","322900107720807731356549153451401585236","30641909703164034095131522789235472829","312449678066938024485074749804097670041","204461751170142905684839284015484469701","275251800527781872931916296749898367687","276736092446101932266423162397011781416","220607371548842682738531909079559250648","193851804838495652505114225811346447401","335330703028102328901877311581203144736"],"threshold":0.9},"deprecated":false,"signature_type":"Line","target":{"file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/96fb144d425f91b124aaab9d56f0305535e6b453","id":"ASB-A-353680402-0273d775"},{"digest":{"length":583,"function_hash":"167051775218518309602972445688464531447"},"deprecated":false,"signature_type":"Function","target":{"function":"assertSafeToStartCustomActivity","file":"src/com/android/settings/users/AppRestrictionsFragment.java"},"signature_version":"v1","source":"https://android.googlesource.com/platform/packages/apps/Settings/+/96fb144d425f91b124aaab9d56f0305535e6b453","id":"ASB-A-353680402-9a42fcc0"}],"fixes":["https://android.googlesource.com/platform/packages/apps/Settings/+/96fb144d425f91b124aaab9d56f0305535e6b453"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-353680402.json"}}],"schema_version":"1.7.5"}