{"id":"ASB-A-365738306","details":"In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an NLS from Settings due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-365738306","CVE-2024-49733"],"modified":"2026-04-22T14:59:17.843400Z","published":"2025-01-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2025-01-01"},{"type":"FIX","url":"https://android.googlesource.com/platform/frameworks/base/+/8516dfb89f99fd119fa12045e5c88633ce7478b8"}],"affected":[{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15-next:0"},{"fixed":"15-next:2025-01-01"}]}],"versions":["15-next"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-365738306-2767a15f","signature_type":"Line","digest":{"line_hashes":["245706110952212737133143465215893512596","8441015199286482723336096750019537574","2203913801863013953610752326245761403","168375376327039914811458805262559478873","312734769563607363589114740525208817475","3544166106377321621015066667677101117","122966738851768452280672697718876528501","120617789216700098775887114430797222613","221077498712494506088861152745117288869","334665111517373998642314040845320111876","201576591833870305689470499159667889194","298517652061270037363155204858969091800","61803440693266216200337439482150002281","87053992900134142751070947667173104721","190583663821423385762165115122030327892","125850764841171638689555196333133084999","155670773850368399915527063221630377781","250238567097922551481524748322810142350","31221265380436497012317990031515028462","196667568110689903248999351757630874598"],"threshold":0.9},"signature_version":"v1","deprecated":false,"target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/234c5e843ca427b1dd47e91e3969f3309dd787bf"},{"id":"ASB-A-365738306-cedaf568","signature_type":"Function","digest":{"length":889,"function_hash":"264098323083350367885933473336084744836"},"signature_version":"v1","deprecated":false,"target":{"function":"reload","file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/234c5e843ca427b1dd47e91e3969f3309dd787bf"}],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/234c5e843ca427b1dd47e91e3969f3309dd787bf"],"severity":"High","spl":"2025-01-01","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-365738306.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12:0"},{"fixed":"12:2025-01-01"}]}],"versions":["12"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-365738306-745a2e79","signature_type":"Function","digest":{"length":889,"function_hash":"264098323083350367885933473336084744836"},"signature_version":"v1","deprecated":false,"target":{"function":"reload","file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"},{"id":"ASB-A-365738306-7c884d9a","signature_type":"Line","digest":{"line_hashes":["245706110952212737133143465215893512596","8441015199286482723336096750019537574","2203913801863013953610752326245761403","168375376327039914811458805262559478873","312734769563607363589114740525208817475","3544166106377321621015066667677101117","122966738851768452280672697718876528501","120617789216700098775887114430797222613","221077498712494506088861152745117288869","334665111517373998642314040845320111876","201576591833870305689470499159667889194","298517652061270037363155204858969091800","61803440693266216200337439482150002281","87053992900134142751070947667173104721","190583663821423385762165115122030327892","125850764841171638689555196333133084999","155670773850368399915527063221630377781","250238567097922551481524748322810142350","31221265380436497012317990031515028462","196667568110689903248999351757630874598"],"threshold":0.9},"signature_version":"v1","deprecated":false,"target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"}],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"],"severity":"High","spl":"2025-01-01","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-365738306.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12L:0"},{"fixed":"12L:2025-01-01"}]}],"versions":["12L"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-365738306-15bd7590","signature_type":"Function","digest":{"length":889,"function_hash":"264098323083350367885933473336084744836"},"signature_version":"v1","deprecated":false,"target":{"function":"reload","file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"},{"id":"ASB-A-365738306-7e35a1f6","signature_type":"Line","digest":{"line_hashes":["245706110952212737133143465215893512596","8441015199286482723336096750019537574","2203913801863013953610752326245761403","168375376327039914811458805262559478873","312734769563607363589114740525208817475","3544166106377321621015066667677101117","122966738851768452280672697718876528501","120617789216700098775887114430797222613","221077498712494506088861152745117288869","334665111517373998642314040845320111876","201576591833870305689470499159667889194","298517652061270037363155204858969091800","61803440693266216200337439482150002281","87053992900134142751070947667173104721","190583663821423385762165115122030327892","125850764841171638689555196333133084999","155670773850368399915527063221630377781","250238567097922551481524748322810142350","31221265380436497012317990031515028462","196667568110689903248999351757630874598"],"threshold":0.9},"signature_version":"v1","deprecated":false,"target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"}],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"],"severity":"High","spl":"2025-01-01","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-365738306.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"15:0"},{"fixed":"15:2025-01-01"}]}],"versions":["15"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-365738306-d31a4043","signature_type":"Function","digest":{"length":889,"function_hash":"264098323083350367885933473336084744836"},"signature_version":"v1","deprecated":false,"target":{"function":"reload","file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/3c44dd35fd99b87e8754a2c67f29b221ef3f69a5"},{"id":"ASB-A-365738306-de76d7a8","signature_type":"Line","digest":{"line_hashes":["245706110952212737133143465215893512596","8441015199286482723336096750019537574","2203913801863013953610752326245761403","168375376327039914811458805262559478873","312734769563607363589114740525208817475","3544166106377321621015066667677101117","122966738851768452280672697718876528501","120617789216700098775887114430797222613","221077498712494506088861152745117288869","334665111517373998642314040845320111876","201576591833870305689470499159667889194","298517652061270037363155204858969091800","61803440693266216200337439482150002281","87053992900134142751070947667173104721","190583663821423385762165115122030327892","125850764841171638689555196333133084999","155670773850368399915527063221630377781","250238567097922551481524748322810142350","31221265380436497012317990031515028462","196667568110689903248999351757630874598"],"threshold":0.9},"signature_version":"v1","deprecated":false,"target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/3c44dd35fd99b87e8754a2c67f29b221ef3f69a5"}],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/3c44dd35fd99b87e8754a2c67f29b221ef3f69a5"],"severity":"High","spl":"2025-01-01","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-365738306.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13:0"},{"fixed":"13:2025-01-01"}]}],"versions":["13"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-365738306-b2133486","signature_type":"Line","digest":{"line_hashes":["245706110952212737133143465215893512596","8441015199286482723336096750019537574","2203913801863013953610752326245761403","168375376327039914811458805262559478873","312734769563607363589114740525208817475","3544166106377321621015066667677101117","122966738851768452280672697718876528501","120617789216700098775887114430797222613","221077498712494506088861152745117288869","334665111517373998642314040845320111876","201576591833870305689470499159667889194","298517652061270037363155204858969091800","61803440693266216200337439482150002281","87053992900134142751070947667173104721","190583663821423385762165115122030327892","125850764841171638689555196333133084999","155670773850368399915527063221630377781","250238567097922551481524748322810142350","31221265380436497012317990031515028462","196667568110689903248999351757630874598"],"threshold":0.9},"signature_version":"v1","deprecated":false,"target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"},{"id":"ASB-A-365738306-fb2c09cc","signature_type":"Function","digest":{"length":889,"function_hash":"264098323083350367885933473336084744836"},"signature_version":"v1","deprecated":false,"target":{"function":"reload","file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"}],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"],"severity":"High","spl":"2025-01-01","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-365738306.json"}},{"package":{"name":"platform/frameworks/base","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"14:0"},{"fixed":"14:2025-01-01"}]}],"versions":["14"],"ecosystem_specific":{"vanir_signatures":[{"id":"ASB-A-365738306-23f02976","signature_type":"Function","digest":{"length":889,"function_hash":"264098323083350367885933473336084744836"},"signature_version":"v1","deprecated":false,"target":{"function":"reload","file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"},{"id":"ASB-A-365738306-504ab2be","signature_type":"Line","digest":{"line_hashes":["245706110952212737133143465215893512596","8441015199286482723336096750019537574","2203913801863013953610752326245761403","168375376327039914811458805262559478873","312734769563607363589114740525208817475","3544166106377321621015066667677101117","122966738851768452280672697718876528501","120617789216700098775887114430797222613","221077498712494506088861152745117288869","334665111517373998642314040845320111876","201576591833870305689470499159667889194","298517652061270037363155204858969091800","61803440693266216200337439482150002281","87053992900134142751070947667173104721","190583663821423385762165115122030327892","125850764841171638689555196333133084999","155670773850368399915527063221630377781","250238567097922551481524748322810142350","31221265380436497012317990031515028462","196667568110689903248999351757630874598"],"threshold":0.9},"signature_version":"v1","deprecated":false,"target":{"file":"packages/SettingsLib/src/com/android/settingslib/applications/ServiceListing.java"},"source":"https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"}],"fixes":["https://android.googlesource.com/platform/frameworks/base/+/e81fa0c19c07a5b6509c3f844b69847a96c7a815"],"severity":"High","spl":"2025-01-01","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-365738306.json"}}],"schema_version":"1.7.5"}