1sealsemantic last-mile verification

Research / Finding

Exported activity accepts actions intended for internal VPN widgets

F-PROTON-VPN-ANDROID-GLANCE-001

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
ProtonVPN/android-appReported fixProtonVPN/android-app

Exported activity accepts actions intended for internal VPN widgets

Fixed in: 5.19.72.0 source and release; installed store binaries not reverified

fixed publicly
details
Finding IDs
F-PROTON-VPN-ANDROID-GLANCE-001
Status
fixed publicly
Fixed in
5.19.72.0 source and release; installed store binaries not reverified
Note
A local Android application could address the exported activity with intent data intended for the VPN widget action path. The 16 July 2026 patch introduces the non-exported InternalMainActivity alias and makes processInternalIntent honor glance_action only when the addressed component is that internal alias. The manifest and handler are present in public release 5.19.72.0. This establishes the source-level separation of external and internal actions; it does not establish a remote network attack, secret recovery, or that every installed store build has been updated. Public-source review does not establish vendor attribution, an assigned severity or a fresh end-to-end retest.

F-PROTON-VPN-ANDROID-GLANCE-001: Access control. Externally supplied activity intents can enter a path intended only for internal widget actions. Reviewed 26 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-PROTON-VPN-ANDROID-GLANCE-001

Security area (1seal assessment): Authorization. Externally supplied activity intents can enter a path intended only for internal widget actions. Reviewed 26 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.