Exported activity accepts actions intended for internal VPN widgets
Fixed in: 5.19.72.0 source and release; installed store binaries not reverified
details
- Finding IDs
- F-PROTON-VPN-ANDROID-GLANCE-001
- Status
- fixed publicly
- Fixed in
- 5.19.72.0 source and release; installed store binaries not reverified
- Note
- A local Android application could address the exported activity with intent data intended for the VPN widget action path. The 16 July 2026 patch introduces the non-exported InternalMainActivity alias and makes processInternalIntent honor glance_action only when the addressed component is that internal alias. The manifest and handler are present in public release 5.19.72.0. This establishes the source-level separation of external and internal actions; it does not establish a remote network attack, secret recovery, or that every installed store build has been updated. Public-source review does not establish vendor attribution, an assigned severity or a fresh end-to-end retest.
F-PROTON-VPN-ANDROID-GLANCE-001: Access control. Externally supplied activity intents can enter a path intended only for internal widget actions. Reviewed 26 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-PROTON-VPN-ANDROID-GLANCE-001
Security area (1seal assessment): Authorization. Externally supplied activity intents can enter a path intended only for internal widget actions. Reviewed 26 Sep 2026.