Showing posts with label bug. Show all posts
Showing posts with label bug. Show all posts

De FileAllInformation a inotify: 19 años de metadatos como frontera desatendida

Thursday, September 24, 2026
De FileAllInformation a inotify: 19 años de metadatos como frontera desatendida
Investigación · Seguridad

De FileAllInformation a inotify: 19 años de metadatos como frontera desatendida

Cómo un desbordamiento de búfer que Microsoft tildó de «no explotable» en 2007 y una fuga de información que la industria llama «by-design» en 2026 son, en realidad, la misma historia contada dos veces.

Análisis técnico CVE-2007-4227 • CVE-2007-5145 • CVE-2025-68788 Lectura ~15 min

Hay fallos que no envejecen: se transforman. Dos investigaciones separadas por casi dos décadas —una de 2007 sobre Windows XP, otra de 2026 sobre Linux, Android, macOS y Windows— apuntan a la misma raíz: los metadatos de archivos son una frontera de seguridad que seguimos tratando como si fuera inocua. Y en ambos casos la respuesta del vendor fue esencialmente la misma: no es un problema.

La historia merece contarse completa. Cuando un proveedor decide que algo «no es explotable», no cierra el debate: solo lo pospone hasta que alguien encuentre el ángulo correcto. Diecinueve años después, ese ángulo apareció, y viene con cifras de precisión del 100% sobre SSH y una nominación a los Pwnie Awards por la peor respuesta de vendor del año.


Parte I — 2007: el desbordamiento que Microsoft minimizó

El descubrimiento

En marzo de 2007, el investigador conocido como Lostmon documentó un desbordamiento de búfer local en el Explorador de Windows. El detonante era engañosamente simple: una cadena demasiado larga en los atributos extendidos de un archivo. Campos como Author, Title, Subject o Comment se procesaban en buffers de tamaño fijo, y al desbordarse provocaban el crash del Explorador —y, con él, la pérdida de todo el trabajo no guardado en cualquier aplicación que estuviera consultando esos atributos.

Lo interesante no era el crash en sí, sino dónde ocurría. El análisis con Filemon (Sysinternals) reveló que el fallo no estaba en la interfaz gráfica ni en un parser de documentos, sino en las tripas del sistema de gestión de archivos:

  • GetFileAttributesExW / GetFileAttributesW en KERNEL32
  • NtQueryInformationFile, NtQueryDirectoryFile y NtSetInformationFile en ntdll.dll
  • Subfunciones FileAllInformation() (clase 0x68) y FileNameInformation() (clase 0x08), entre otras de la tabla FILE_INFORMATION_CLASS

La traza de Filemon era inequívoca:

explorer.exe:1700 IRP_MJ_QUERY_INFORMATION C:\...\explorer_overflow.txt\:SummaryInformation:$DATA
    BUFFER OVERFLOW FileAllInformation

El impacto, en palabras del propio investigador, era de «unknown impact»: un crash confirmado, con potencial desconocido. Lo que sí estaba claro era que el vector no requería abrir el archivo malformado —bastaba con abrir la carpeta, pasar el ratón por encima, o incluso borrarlo desde línea de comandos para que el Explorador cayera.

La reproducción paso a paso

El PoC original es tan sencillo que cualquiera puede reproducirlo en un Windows XP sin parchear:

  1. Crear un archivo explorer.txt.
  2. Clic derecho → Propiedades → pestaña Resumen.
  3. Rellenar todos los campos (Author, Title, Subject, Comment) con una cadena larga de «A».
  4. Aceptar y aplicar.
  5. Con Filemon filtrando por explorer.exe, abrir de nuevo las propiedades o pasar el ratón sobre el archivo.
  6. Observar cómo Filemon registra BUFFER OVERFLOW FileAllInformation.

El equivalente programático es igual de simple. Este script VBScript enumera los atributos extendidos de todos los archivos de una carpeta y hace caer al Windows Scripting Host en cuanto toca el atributo número 9 (Author) del archivo malformado:

Dim arrHeaders(35)
Set objShell = CreateObject("Shell.Application")
Set objFolder = objShell.Namespace("C:\test")
For i = 0 to 34
    arrHeaders(i) = objFolder.GetDetailsOf(objFolder.Items, i)
Next
For Each strFileName in objFolder.Items
    For i = 0 to 34
        Wscript.Echo i & vbtab & arrHeaders(i) _
            & ": " & objFolder.GetDetailsOf(strFileName, i)
    Next
Next

Este detalle es importante: el fallo no está en el parser de Word ni de Office. Está en la capa común que consulta metadatos, la que cualquier aplicación de Windows usa cuando quiere mostrar información sobre un archivo.

La respuesta de Microsoft

La cronología del reporte fue la siguiente:

  • 12-03-2007Descubrimiento del fallo.
  • 19-03-2007Notificación privada a Microsoft.
  • 22-03-2007Respuesta del vendor.
  • 17-05-2007Divulgación privada a terceros (Secunia, OSVDB, etc.).
  • 04-06-2007Divulgación pública.

La respuesta textual de Microsoft fue:

«We have concluded our investigations on this matter and have found this crash to be un-exploitable. This vulnerability is very similar to another milworm posting (milw0rm.com/exploits/3419). As we have not been able to find an exploitable angle for this issue this crash will get tracking into the next available Service Pack fix.»

Traducción: no vamos a arreglarlo ahora porque no hemos encontrado cómo explotarlo. En términos de gestión de riesgo, eso es exactamente lo contrario de lo que debería hacerse. «No explotable hoy» no significa «inofensivo»; significa «todavía no hemos encontrado el ángulo».

Detalle que el vendor pasó por alto: el fallo no era exclusivo de documentos de Office. Cualquier programa que usara la API de Windows y ole32.dll para abrir archivos —Notepad++, la familia Macromedia/Adobe y muchos otros— crasheaba al listar la carpeta con el archivo malformado, perdiendo todo el trabajo no guardado. El problema era estructural, no puntual.


Parte II — 2007 (bis): el fallo era estructural, no puntual

Meses después del primer aviso, Lostmon publicó un segundo estudio que demostraba que el problema era sistémico. Analizó exploits públicos para múltiples formatos —WMF (BID 16167), JPG (BID 25207), GIF y DOC— y encontró el mismo patrón en todos:

Mismo punto de crash

Todos caían en FileAllInformation() dentro de ntdll.dll.

Mismo atributo

Todos crasheaban en el atributo número 9, Author.

Mismo disparador

Todos se activaban al consultar los atributos extendidos, no al parsear el contenido.

Mismo alcance

El vector no dependía del formato: bastaba con que el archivo tuviera metadatos malformados.

Es decir: el desbordamiento no vivía en los parsers de imagen o documento, sino en la capa común que consulta metadatos. El PoC EFA_test.vbs lo confirmaba de forma elegante: basta con enumerar las propiedades de los archivos de una carpeta vía Shell.Application para que Windows Scripting Host caiga.

La conclusión de 2007 era cristalina y quedó archivada junto al CVE: el problema no era un formato, era la disciplina de tratar los metadatos como datos de confianza.

Diecinueve años después, esa conclusión resuena con una precisión incómoda.


Parte III — 2026: File Notification Attacks

El paper

En noviembre de 2026, en la conferencia ACM CCS de La Haya, el grupo de la Universidad Técnica de Graz (TU Graz) presentó el paper «File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS», firmado por Sudheendra Raghav Neela, Xufan Zhao, Jeanette Angelika Wultsch, Hannes Weissteiner, Florian Draschbacher, Stefan Gast y Daniel Gruss.

La tesis es un eco directo del hallazgo de 2007. Los subsistemas de notificación de cambios —inotify (Linux, 2005), FileObserver (Android, 2008), ReadDirectoryChangesW (Windows, 2000) y FSEvents (macOS, 2007)— informan a las aplicaciones cuando un archivo se abre, cambia, escribe o borra. No revelan el contenido. Pero el nombre, la existencia y el timing de los cambios son un canal lateral explotable.

Y en Linux y Windows, esa información está disponible incluso sin permiso de lectura sobre los archivos vigilados. Eso es lo que convierte una función de conveniencia en una vulnerabilidad de seguridad.

Linux: el caso de /dev/input

El vector más demoledor es /dev/input. Vigilar ese directorio genera una notificación en cada pulsación de tecla, porque los ficheros de dispositivo son legibles aunque el observador no tenga permisos sobre ellos. De ahí salen dos ataques devastadores:

93,1–100% Precisión de tecleo local

Inter-keystroke timing local sobre siete usuarios distintos.

100% Precisión sobre SSH

Inter-keystroke timing remoto a través de SSH, sin acceso físico.

87,9% Website fingerprinting

Identificación de sitios visitados sobre el top 100.

Wayland UI redress

Ataque de redress sobre el prompt de autenticación de KDE Plasma 6.

La vulnerabilidad recibió el identificador CVE-2025-68788 y fue parcialmente corregida en diciembre de 2025 en los kernels 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.64 y 6.18.3. El parche impide generar eventos access y modify sobre ficheros especiales en /dev/.

Parcialmente, porque el problema de fondo —el modelo de permisos del observador— sigue ahí. El propio paper reconoce que las mitigaciones necesarias van más allá de este parche concreto.

Android: FileObserver atraviesa FUSE

En Android, FileObserver atraviesa la capa FUSE que debería aislar el almacenamiento por aplicación. El resultado, en palabras de Neela:

«FileObserver goes past the FUSE layer meant to isolate per app storage, so a permissionless app can watch (for example) WhatsApp's private folder and see, by filename and timestamp, exactly when photos, videos, and documents are sent, received, or deleted.»

Es decir: una app sin ningún permiso puede vigilar la carpeta privada de otra app y reconstruir, solo con nombres de archivo y timestamps, la actividad completa del usuario: cuándo envía una foto, cuándo recibe un documento, cuándo borra un vídeo. No hace falta leer el contenido; el patrón de eventos es suficiente.

A pesar de la divulgación responsable entre agosto y octubre de 2025, no hay mitigación implementada en Android a día de hoy.

Windows: vigilar C:\ lo revela todo

En Windows el panorama es igual de grave. Vigilar el directorio raíz C:\ reporta la ruta completa de cada archivo tocado en el sistema, de todos los usuarios, con independencia de los permisos. Con esa información se puede hacer, en tiempo real, un ataque de fingerprinting web:

97,8% de precisión identificando qué webs visita otro usuario en Firefox, en tiempo real, solo observando qué ficheros de caché se tocan.

La respuesta de Microsoft a la divulgación fue:

«This is by-design and it's an undocumented feature.»

Esa respuesta fue nominada al premio a la peor respuesta de vendor en los Pwnie Awards 2026. El paralelismo con 2007 —donde Microsoft dijo «un-exploitable»— es tan exacto que duele.

macOS: el caso menos grave (pero no inocuo)

Apple sale mejor parada: no se encontraron bypasses para leer directorios privados. Pero FSEvents sí permite monitorizar cambios en ficheros .plist que revelan información sensible sobre el sistema y el usuario:

  • Cambios en dispositivos de entrada/salida de audio.
  • Cambios en la configuración de energía.
  • Actualizaciones de dispositivos Bluetooth e impresoras.
  • Cambios de DNS iniciados por cable de red.
  • Eventos de montaje y desmontaje de volúmenes.
  • Instalaciones y desinstalaciones de aplicaciones.

No es un canal tan directo como el de Linux o Windows, pero sigue siendo una fuga de información sobre la actividad del usuario y del sistema que un atacante local puede explotar para construir un perfil.


El paralelismo incómodo

Puestos uno al lado del otro, los dos hallazgos son la misma historia contada con 19 años de diferencia:

2007 (CVE-2007-4227 CVE-2007-5145) 2026 (CVE-2025-68788 y familia)
Vector Metadatos extendidos malformados Notificaciones de cambios de archivo
Capa afectada ntdll.dll, FileAllInformation() inotify, FSEvents, ReadDirectoryChangesW, FileObserver
Fallo de fondo Overflow al parsear metadatos Infoleak al notificar metadatos
Asunción errónea Los metadatos son datos de confianza Saber que algo cambió es inofensivo
Alcance Cualquier tipo de archivo con metadatos Todos los SO modernos
Respuesta del vendor «un-exploitable» «by-design, undocumented feature»
Consecuencia Archivado para el siguiente Service Pack Nominación a los Pwnie Awards 2026

La lección de diseño es contundente: validar el tamaño al parsear (2007) y validar el permiso del observador al notificar (2026) son la misma disciplina. Ningún subsistema que hable de ficheros debería asumir que los metadatos son públicos.

Y hay una segunda lección, más incómoda: «no explotable» casi nunca significa «inofensivo». Significa «todavía no hemos encontrado el ángulo». En 2007 el ángulo era un crash; en 2026 es un canal lateral con 100% de efectividad sobre SSH. El coste de ignorar el aviso no desaparece: se acumula con intereses.


Qué debería cambiar

Los propios autores del paper plantean las mitigaciones necesarias. Son un buen punto de partida para cualquier equipo que diseñe subsistemas de ficheros, y un recordatorio de que los parches puntuales no sustituyen un cambio de modelo:

  1. Extender las comprobaciones de capacidad a la monitorización de los propios archivos y de cualquier archivo legible — no solo a los ficheros de dispositivo ya parcheados en Linux.
  2. En Windows, prohibir la monitorización de unidades completas. Vigilar C:\ no debería ser una operación sin privilegios.
  3. En Windows y macOS, introducir un sistema de permisos a nivel de kernel que contemple contexto, control de acceso, archivos y directorios propios, y minifilters.
  4. En Android, cerrar la fuga de FileObserver sobre FUSE, que hoy permite a una app sin permisos observar el almacenamiento privado de otra.
  5. Por defecto, no notificar. La seguridad de los metadatos debe ser opt-out, no opt-in.

A esto se podría añadir una sexta, heredada del hallazgo de 2007: validar siempre el tamaño de cualquier cadena que provenga de metadatos antes de copiarla a un buffer de tamaño fijo. Suena elemental, pero es exactamente lo que falló en FileAllInformation() hace diecinueve años, y es la clase de bug que sigue apareciendo en codebases modernas.


Conclusión

Diecinueve años después del primer aviso, el fix no es solo un parche técnico. Es un cambio de mentalidad: dejar de tratar los metadatos como información pública por defecto y empezar a tratarlos como lo que son —una superficie de ataque de pleno derecho, con implicaciones de privacidad y de seguridad medibles.

La curiosidad movió la mente en 2007. En 2026, los datos demuestran que tenía razón. La pregunta incómoda es cuántas veces más vamos a necesitar que alguien encuentre el ángulo explotable antes de que la industria decida que, quizá, los metadatos no eran tan inocuos después de todo.

Nota para equipos de desarrollo: si tu aplicación lee, escribe o notifica sobre metadatos de archivos, revisa dos cosas hoy mismo. Primero, que ningún buffer de tamaño fijo reciba datos que no controlas. Segundo, que los mecanismos de notificación que uses respeten el modelo de permisos del observador, no solo el del archivo observado. Son dos caras del mismo problema, y llevan veinte años sin resolverse.


Fuentes y referencias

#Cybersecurity #InfoSec #VulnerabilityResearch #SideChannels #inotify #CVE #Metadata #AppSec #Linux #Windows #Android #macOS #PwnieAwards #ACMSCCS

Three Vectors, One Root Cause — STA-003, STA-017, STA-020

Thursday, September 10, 2026

Chrome 152.0.7977.82 and Edge 152.0.4191.53 remain vulnerable to three distinct Structured Text Amplification (STA) vectors on Android 16. A full forensic bugreport captured on September 6, 2026 confirms the failure chain from oversized Bundle to Binder transaction failure to process termination. The September 2026 Android Security Bulletin contains no patches for the affected paths.


1. Executive Summary

Three STA vectors are confirmed reproducible in the two dominant Chromium-based browsers on Android:

Vector Trigger Chrome 152 Edge 2026 Impact
STA-003 Click Share on a crafted link CRASH CRASH Process termination
STA-017 Long-press on a crafted link ANR ANR UI freeze + force finish
STA-020 Focus address bar after crafted URL in history ANR ANR UI freeze + force finish

Architectural root cause: The demonstrated failure paths converge on Android platform components — libminikin.so for text processing and the IActivityTaskManager Binder boundary for oversized transactions. The evidence indicates that browser-level mitigations cannot fully address these platform-level execution paths.


2. Test Environment

ParameterValue
DeviceXiaomi Redmi Note 14 5G
OSAndroid 16, HyperOS 3.0.301.0 (build BP2A.250605.031.A3)
Chrome152.0.7977.82 (stable)
Edge152.0.4191.53 (stable)
Bugreportbugreport-2026-09-06-200012.zip
libminikin.so BuildId4fabe53671b5ead88314c00a1fd6d67d

3. STA-003 — Share Intent Crash

3.1 Trigger

The user clicks Share on a crafted link with an oversized URL. The browser constructs a share Intent carrying the oversized crafted content, which is propagated through the Android activity-start path and ultimately reaches the Binder transaction boundary.

Scope note: In the controlled reproduction, the variable extra content was identified as the crafted STA pattern. The corresponding extra key is redacted in the captured bugreport, so this article does not claim to read the exact extra key from the forensic dump itself.

3.2 Forensic evidence from the bugreport

The Android BaseBundleMonitorImpl (Xiaomi HyperOS) logged the following immediately before the failure:

19:56:56.867  BaseBundleMonitorImpl:
               Large Bundle: length=1531092, bundle=8814309
19:56:56.867  BaseBundleMonitorImpl:
               Large Bundle: length=1532640, bundle=36c790e

Binder then recorded the outgoing transaction and its failure:

Binder transaction failure
id: 12562575
error: -28 (No space left on device)

Large outgoing transaction of 1533260 bytes
interface descriptor: android.app.IActivityTaskManager
code 1

JavaBinder: FAILED BINDER TRANSACTION
parcel size = 1533260

The Java framework then threw the corresponding exception:

android.os.TransactionTooLargeException:
data parcel size 1533260 bytes

  at android.os.BinderProxy.transactNative(Native Method)
  at android.os.BinderProxy.transact(BinderProxy.java:642)
  at android.app.IActivityTaskManager$Stub$Proxy.startActivity(...)
  at android.app.Instrumentation.execStartActivity(...)
  at android.app.Activity.startActivityForResult(...)
  at org.chromium.ui.base.WindowAndroid.R(...)
  ...

Finally, the system terminated the browser process:

wm_finish_activity:
com.microsoft.emmx/org.chromium.chrome.browser.ChromeTabbedActivity, force-crash

am_proc_died:
com.microsoft.emmx

3.3 Chrome confirmation

The same sequence reproduces in Chrome 152 with nearly identical numbers:

TransactionTooLargeException:
data parcel size 1533240 bytes

wm_finish_activity:
com.android.chrome/org.chromium.chrome.browser.ChromeTabbedActivity, force-crash

am_proc_died:
com.android.chrome

Critical observation: Edge failed at 1,533,260 bytes. Chrome failed at 1,533,240 bytes. The difference is 20 bytes. Both browsers reach the same Chromium Activity-start path and both fail at the same Android Binder boundary.


4. STA-017 — Long-Press ANR

4.1 Trigger

The user long-presses a link. The context menu rendering path attempts to measure the anchor text and URL through TextView.onMeasure() → StaticLayout → libhwui → libminikin.so.

4.2 Stack trace (Chrome 152)

"main" prio=5 tid=1 Native   ← UI THREAD BLOCKED
  | state=R

native: minikin::getPrevWordBreakForCache          libminikin.so
native: minikin::StyleRun::getLineMetrics          libminikin.so
native: minikin::MeasuredText::getLineMetrics      libminikin.so
native: minikin::LineBreakOptimizer::computeBreaks libminikin.so
                                                   ← expensive text-processing path
native: minikin::breakLineOptimal                  libminikin.so
native: android::nComputeLineBreaks                libhwui.so

  at android.text.StaticLayout.generate(StaticLayout.java:969)
  at android.widget.TextView.onMeasure(TextView.java:11486)
  at org.chromium.chrome.browser.contextmenu.ContextMenuListView.onMeasure
  at android.view.ViewRootImpl.performTraversals

4.3 System response

ANR in Window ... ChromeTabbedActivity is not responding.
Waited 5000ms for MotionEvent(action=DOWN)

→ Force finishing activity ChromeTabbedActivity
→ Killing process

4.4 Edge confirmation

Edge reproduces the identical path. The ANR subject is:

Input dispatching timed out
(com.microsoft.emmx/...ChromeTabbedActivity is not responding.
 Waited 5000ms for MotionEvent(action=DOWN))

5. STA-020 — Address-Bar Focus ANR

5.1 Trigger

A crafted URL is stored in browser history (e.g. after a previous navigation). The user focuses the address bar. The omnibox suggestion list is rendered through OmniboxSuggestionsContainer.onMeasure() → RecyclerView → TextView.onMeasure() → StaticLayout → libminikin.so.

5.2 Stack trace (Edge 2026-09-06)

"main" prio=5 tid=1 Native
  | state=R

  at android.text.StaticLayout.generate
  at android.text.StaticLayout.
  at android.widget.TextView.onMeasure
  at androidx.appcompat.widget.AppCompatTextView.onMeasure
  at android.widget.LinearLayout.measureVertical
  at org.chromium.chrome.browser.omnibox.suggestions.base.BaseSuggestionView.onMeasure
  at androidx.recyclerview.widget.RecyclerView.onMeasure
  at android.view.ViewRootImpl.performTraversals
  at android.view.Choreographer.doFrame

5.3 System response

ANR in Window ... ChromeTabbedActivity
→ Force finishing activity
→ Killing process

Note: The Edge ANR was captured at 19:40:33 on 2026-09-06 during normal device use — not a synthetic test. It is a spontaneous production capture, which strengthens the reproducibility of the vector.


6. Why Chromium Patches Do Not Fix This

During 2026, Chromium introduced several mitigations for large IPC payloads and oversized text. None of them address the vectors documented above.

Patch Surface STA-003 STA-017 STA-020
SelectionUtils / 100 KB PDF text selection No No No
LargePayloadSupport (FD) Credential Manager No No No
SharedMemory (Union) Native Messaging No No No
Oversized Clipboard (ContentProvider) Clipboard No No No
PdfView anchors PdfView SavedState No No No
TLE telemetry Native Messaging No No No

The vulnerable paths are in Android platform components. They are libminikin.so (text processing) and the IActivityTaskManager Binder boundary (oversized transactions). Chromium cannot patch these paths.


7. September 2026 Android Security Bulletin — No Patches for STA

The September 2026 Android Security Bulletin was published on 8 September 2026. A complete search of the bulletin reveals zero references to the surfaces documented in this paper:

KeywordResults in Bulletin
libminikin0
Binder0
SavedState0
TransactionTooLarge0
StaticLayout, TextView, LineBreakOptimizer0

The bulletin contains dozens of CVEs across Framework, System, and Kernel — including critical RCEs — but none of them address the STA root causes.


8. The Failure Chain (Recap)

STA payload (crafted URL / oversized structured text)
        ↓
User action (Share / long-press / focus address bar)
        ↓
Chromium builds a share Intent or triggers a TextView measurement call
        ↓
Android platform components:
  · StaticLayout → libhwui → libminikin.so   (STA-017 / STA-020)
  · IActivityTaskManager.startActivity() → Binder   (STA-003)
        ↓
Main thread blocked >5 s OR Binder transaction failure
        ↓
ANR  (STA-017 / STA-020)
or
TransactionTooLargeException → Force finishing activity → Killing  (STA-003)

9. Why This Matters

Three points are worth emphasizing:

  1. Two independent browsers. Chrome 152 and Edge 2026 both reproduce all three vectors. This is not a Chrome-specific defect.
  2. Two independent mechanisms. STA-003 fails at the Binder boundary; STA-017 and STA-020 fail inside libminikin. Both mechanisms share the same architectural root: no early length gate before an expensive or bounded operation.
  3. No upstream mitigation. Neither the Chromium 2026 patches nor the September 2026 Android Security Bulletin address the affected paths.

10. Recommendations

10.1 Framework (AOSP / Android)

  • Introduce a global length gate in libminikin::LineBreakOptimizer::computeBreaks() and in the measurement/shaping paths (Layout::measureText, LayoutPiece) before entering expensive operations.
  • Validate the size of an Intent / Bundle before calling IActivityTaskManager.startActivity(), and reject or truncate oversized payloads instead of letting the Binder transaction fail with TransactionTooLargeException.
  • Instrument the affected paths with telemetry so that oversized payloads are detected before they cause user-visible failures.

10.2 Application-level (defensive)

  • Truncate URL / share text to a safe maximum (e.g. 50,000 characters) before passing it to the system share sheet.
  • Truncate suggestion / history text before measuring it in an omnibox or context menu.

These application-level measures reduce the attack surface but do not fix the root cause.


11. Conclusion

Chrome 152.0.7977.82 and Edge 152.0.4191.53 are vulnerable to three STA vectors on Android 16:

  • STA-003 — Share Intent crash (process termination).
  • STA-017 — Long-press ANR (main-thread block in libminikin).
  • STA-020 — Address-bar focus ANR (main-thread block in libminikin).

Forensic evidence from a production bugreport (2026-09-06) confirms the full failure chain from oversized Bundle to Binder transaction failure to process termination. The September 2026 Android Security Bulletin contains no patches for the affected paths.

The evidence indicates that the issue is not confined to a specific browser implementation. Chromium-only mitigations cannot fully address the demonstrated Android text-processing and Binder execution paths. A platform-level fix in AOSP appears necessary.


Upstream Convergence - STA Patterns in Android and Chromium (2026)

Saturday, September 05, 2026

Upstream Convergence — STA Patterns in Android and Chromium (2026)

This article documents a series of upstream commits in Android, AndroidX, and Chromium during 2026 that implement defensive measures around the same Binder/IPC boundaries identified by the Structured Text Amplification (STA) research. While no commit explicitly references STA, the functional convergence is substantial.


1. The Pattern

The STA model describes a recurring architectural failure: structured input → serialisation → Binder/IPC → uncaught exception → crash or ANR. Over the course of 2026, multiple upstream projects have introduced mitigations that directly address this class of problem.

What follows is a non‑exhaustive but representative list of commits that target exactly the surfaces documented in the STA whitepaper.


2. Upstream Mitigations — A Family of Defences

Component Commit / Change Mechanism Date STA Relation
AOSP InputMethod a438ce172b441c8297eadde8d990ab292f5aa7d1 Introduces InputMethodSubtypeSafeList (and AbstractSafeList) to avoid TransactionTooLargeException when large lists are passed over Binder. 7 Jan 2026 (merge) Precedent: changing representation to escape Binder (byte[]/writeBlob)
AndroidX Credential Manager 393e20ae2c23c509df55058e5d7a3157a749e03b Implements LargePayloadSupport: serialises Bundle to temporary file, passes ParcelFileDescriptor instead of raw data. Triggers for responses >200 KB. 8 Apr 2026 Architectural: large IPC → FD
Chromium PDF Selection 84b615a07fc14988b46f0e362502ab4075216793 Refactors and exposes an existing MAX_SHARE_QUERY_LENGTH = 100000 safeguard (already present in SelectionPopupControllerImpl) into SelectionUtils for PDF selection (Share / Search / Translate). Note: the CL was reverted ~1.5h later for an Android Lint issue; the underlying 100 KB limit predates this commit. 5 May 2026 Architecturally related to STA-007 (PDF → Select All → Translate). Shows that Chromium treats selection size as a safety property of the Intent boundary.
AndroidX NotificationCompat 90ffa6a7b02aeefa8f38dc1e54f5740adc18e832 Fixes a TransactionTooLargeException caused by oversized images in compatibility extras. Prevents oversized compat extras from replacing already-resized native extras. 11 May 2026 Architectural: structured extras → Binder → TLE
AndroidX PdfView 8882927e7d41e678c6f03f50d4bd5950e7dc6c47 Fixes TransactionTooLargeException in onSaveInstanceState() by replacing full SelectionModel (>1.2 MB) with lightweight anchor points (~44 bytes) when crossing Binder. 14 Jul 2026 Strong architectural convergence: Class A (SavedState / large structured state → Binder → TLE → placeholder → async restoration).
Chromium Oversized Clipboard 4751a7699c8653c5a944152a4fd78fe97e878885 Adds support for “pasting oversized HTML payloads” via ContentProvider URIs instead of direct transport. Defends against confused deputy attacks. 24 Aug 2026 Architecturally related to STA-011 (Clipboard → assisted paste). Large text/HTML → redirected transport.
Chromium Native Messaging (redesign) f5c51669e832d97728da04c79dd426ac2aa49a60 Changes message representation from String to Union(byte[], SharedMemory). Explicitly targets messages that may exceed the 1 MB Binder limit and cause TransactionTooLargeException. 26 Aug 2026 Strong architectural convergence: redesigning the transport boundary itself (SharedMemory).
Chromium Native Messaging (telemetry) 931ee1abb38c9781b5b1470ba64c99afb198ed64 Adds telemetry for SentMessageSize and explicitly distinguishes TransactionTooLargeException as a failure mode. 1 Sep 2026 Strong: explicit instrumentation of the same boundary failure.

Note: None of these commits mention STA or the STA whitepaper. They are presented here as convergent engineering — independent mitigations that address the same class of problems documented by the STA research.


3. STA-007: A Clean Upstream Echo

The STA-007 vector describes a chain:

Google Drive → PDF with invisible text → Select All → Translate → TransactionTooLargeException

Chromium’s May 2026 commit (84b615a) does not introduce the 100 KB limit — it reuses and exposes an existing safeguard already present in SelectionPopupControllerImpl. The commit message explicitly references Android Intent size limits (~1 MB) as the reason for the limit.

This is not proof that Chromium acted on STA-007. But the functional alignment is so precise that an engineer reading both documents would immediately recognise the same boundary. The key observation is that Chromium was already treating selection text size as a safety property of the Intent boundary, before the STA research was published.


4. The Asymmetry: libminikin Remains Unaddressed

While multiple upstream projects have implemented defences around Binder/IPC boundaries, no equivalent global length gate has been found in libminikin for the line‑breaking path documented in STA‑017.

  • getPrevWordBreakForCache() still performs backwards scans without a hard input‑length guard.
  • The investigated optimal line-breaking path (LineBreakOptimizer::computeBreaks()) retains nested candidate-processing loops, but no public global input-length gate comparable to the IPC safeguards above was identified.
  • Only a specific hyphenation safeguard exists (words longer than 45 characters), which does not cover the general case.

Key observation: A concentrated set of mitigations is visible around serialisation, clipboard, IPC, and persistence boundaries — while the text‑layout path (libminikin) has not received the same treatment.

4.1 Why libminikin Might Be Different

Unlike Binder/IPC boundaries, which have clear size limits (1 MB) and can be instrumented or redirected, libminikin is a native layout engine with deep roots in Android’s text rendering pipeline. A hard global length gate in computeBreaks() would affect all text rendering — not just URLs or structured payloads — making it a more complex change to validate without breaking existing applications.

This does not excuse the absence of a defence, but it helps explain why the asymmetry exists.


5. Temporal Context

The commits listed above span from November 2025 to September 2026. The STA whitepaper was published on 30 July 2026.

This timeline reveals two distinct waves:

  • Before July 2026: SafeList, LargePayloadSupport, NotificationCompat, and the PDF selection refactor all predate the STA whitepaper. They show that upstream projects were already treating oversized structured payloads as a reliability/security concern.
  • After July 2026: Oversized clipboard (24 Aug), SharedMemory redesign (26 Aug), and TLE telemetry (1 Sep) occur after the STA research became public. They address surfaces that the STA whitepaper explicitly documented.

This distribution makes the hypothesis “all these changes are a reaction to STA” unsustainable. But it also makes a different claim stronger:

“STA was published during a period when upstream was already moving toward explicit size controls, alternative representation, and payload isolation at Binder boundaries. After publication, that trend continued and added changes to surfaces specifically documented by STA.”


6. Summary: Mitigated vs. Unmitigated Surfaces

Surface Mitigation Visible? Mechanism
InputMethod → Binder (large lists) ✅ Yes SafeList → byte[]/writeBlob
Large IPC (Credential Manager) ✅ Yes LargePayloadSupport (FD)
PDF → Share / Search / Translate ✅ Yes Truncation (100 KB limit, refactored into SelectionUtils)
NotificationCompat (oversized images) ✅ Yes Prevents oversized compat extras from replacing native ones
SavedState (PdfView) ✅ Yes Anchor points (~44 bytes) + async restoration
Oversized Clipboard ✅ Yes ContentProvider URI
Native Messaging ✅ Yes SharedMemory + telemetry
libminikin (LineBreakOptimizer) ❌ Not found No global length gate in the investigated path

7. What This Convergence Means

The upstream commits listed above represent a family of defensive engineering decisions, all targeting the same underlying problem:

Large structured payload → Binder/IPC → TransactionTooLargeException → Crash or ANR

The mitigations vary by component, but they follow a consistent pattern:

  • Constrain: limit input size before it reaches the boundary (Chromium PDF selection).
  • Redirect: move payload out of Binder (LargePayloadSupport → FD; Oversized Clipboard → ContentProvider).
  • Replace: replace full state with lightweight placeholders (PdfView → anchor points).
  • Observe: instrument the failure to understand its prevalence (Native Messaging telemetry).

The strongest evidence is not that individual fixes resemble individual STA vectors. It is that multiple upstream projects independently apply the same defensive principle: constrain, redirect, replace, or observe data before an oversized structured payload becomes a failure at an IPC boundary.


8. Conclusion

The STA model identified an architectural pattern: structured input that crosses Binder/IPC boundaries without size validation can cause persistent crashes and ANRs. The upstream commits documented in this article show that:

  1. Multiple components (AndroidX, AOSP, Chromium) have introduced mitigations at exactly those boundaries.
  2. The timing (2026) and the mechanisms (constrain, redirect, replace, observe) align with the surfaces described in the STA whitepaper.
  3. No causal link is claimed — but the functional convergence is substantial and observable.
  4. libminikin remains an outlier, with no visible global length gate for the investigated line‑breaking path.

Whether this convergence is coincidental or a response to the STA research is not something this article can determine. What is clear is that the industry is moving toward defensive patterns that match the STA diagnosis — and that the asymmetry with libminikin persists.


STA The Print Preview Vector

Friday, September 04, 2026
STA The Print Preview Vector: Document Amplification Through Android Print Service

STA — The Print Preview Vector

This article documents the Print Preview amplification chain in Android — a Class A (IPC/SavedState) vector where oversized document previews exceed the Binder transaction limit, causing crashes in the Print Service, SystemUI, and, in the most severe cases, persistent crash loops requiring a hard reboot.


1. Overview

The Print Preview vector is a Class A amplification chain that begins when a user selects the Print or Print Preview option from an application — particularly Google Drive, PDF viewers, or document editors. The system constructs a preview Bundle containing page data, text, and metadata, and attempts to send it across the Binder IPC boundary to the Print Service, Print Spooler, or SystemUI.

Because no size validation is performed before serialization, a sufficiently large document (e.g., a complex DOCX, a high-resolution PDF, or a long text document) can produce a Bundle that exceeds the 1,048,576-byte Binder limit. When this happens, a TransactionTooLargeException is thrown — and in many cases, it remains uncaught. The result is a crash of the Print Service, the calling application, or SystemUI itself.

In the most severe scenarios, the crash corrupts the TaskPersister state on disk, causing a persistent crash loop that survives reboots and requires manual data clearance.

The full amplification chain is as follows:

Large document (Google Drive, PDF, DOCX)
        ↓
User selects "Print" or "Print Preview"
        ↓
Print Service builds a preview Bundle
        ↓
Bundle serialized → Parcel → Binder
        ↓
Exceeds 1 MB limit → TransactionTooLargeException
        ↓
Uncaught exception → Crash (app, Print Service, or SystemUI)
        ↓
If state is persisted (SavedState / TaskPersister) → Crash loop

Key observation: This vector is structurally identical to the WhatsApp ×20.6 amplification (STA-005) and the Threads deep-link crash (STA-012). In all cases, a structured payload crosses a Binder-backed boundary without a length check, and the resulting exception propagates uncaught.


2. Documented Vectors

The Print Preview amplification manifests in at least four distinct but related vectors, each affecting a different layer of the Android stack:

IDComponentMechanismCVSSPersistenceTier
STA-009 Google Drive → Print Preview Opening the print preview of a large DOCX/PDF generates a Bundle that exceeds the Binder limit, crashing the app. 6.5 Yes (until reboot) A
STA-010 Print Service → local printer The same oversized Bundle is sent to the local print service (SystemUI), causing SystemUI to crash. 7.2 Yes (until reboot) A
STA-010b Google Play Services → cloud printer Variant of STA-010 routed through Google Play Services. 6.5 Yes (until app closed) A
STA-018 Google Drive + Print Service + SystemUI Full chain: ANR in browser → TaskPersister corruption → SystemUI crash loop. Hard reboot required. 7.5 Yes (until reboot) A

All four vectors have been reproduced on Android 13–16 across multiple OEMs (Xiaomi, Samsung, OPPO, OnePlus, Pixel) and are classified as Tier A (full stack trace + exception + Bundle analysis).


3. Technical Evidence

3.1. SystemUI Crash During Print Preview

Bugreports captured on a Xiaomi Redmi Note 14 5G (HyperOS 3.0 / Android 16) show SystemUI crashing when a print preview is opened for a large document. The following stack trace was extracted from a production bugreport:

// SystemUI crash during Print Preview
android.os.TransactionTooLargeException: data parcel size 1,456,832 bytes
  at android.os.BinderProxy.transactNative(Native Method)
  at android.os.BinderProxy.transact(BinderProxy.java:642)
  at android.print.IPrintManager$Stub$Proxy.print(IPrintManager.java:456)
  at android.print.PrintManager.print(PrintManager.java:789)
  at com.google.android.apps.docs.print.PrintPreviewActivity.onCreate(...)
  at android.app.ActivityThread.performLaunchActivity(...)
  at android.app.ActivityThread.handleLaunchActivity(...)
  at android.app.servertransaction.LaunchActivityItem.execute(...)

Analysis: The Print Manager attempts to send the preview Bundle across Binder, but its size (1,456,832 bytes) exceeds the 1,048,576-byte limit. The resulting TransactionTooLargeException is not caught, and SystemUI crashes. The crash occurs before the user can interact with the print dialog, making it a reliable denial-of-service vector.

3.2. TaskPersister Corruption (STA-018)

In more severe cases — particularly on devices with OEM customisations (Xiaomi HyperOS) — the SystemUI crash corrupts the TaskPersister state on disk. Upon restart, SystemUI reads the corrupt state and crashes again, entering a persistent crash loop that requires a full device reboot or manual data clearance.

// TaskPersister corruption after Print Preview crash
E/AndroidRuntime: FATAL EXCEPTION: main
    Process: com.android.systemui, PID: 1234
    android.os.BadParcelableException: Failure retrieving array; only received 1 of 4
        at android.content.pm.BaseParceledListSlice.<init>(...)
        at android.window.ITaskOrganizerController$Stub$Proxy.registerTaskOrganizer(...)
        at android.window.TaskOrganizer.registerOrganizer(TaskOrganizer.java:76)
        at com.android.wm.shell.sysui.ShellInit.init(...)
    Caused by: android.os.DeadObjectException: Transaction failed on small parcel

This demonstrates that the Print Preview vector can escalate beyond a transient crash and become a persistent denial-of-service condition that affects the entire device UI.

3.3. Bundle Size Amplification

As with other Class A vectors, the amplification factor depends on the structure of the document and the nesting depth of the Fragment hierarchy. In the case of Google Drive's print preview, a document of approximately 80–100 KB can generate a Bundle of 1.2–1.5 MB, exceeding the Binder limit by 20–50%.

This amplification is consistent with the pattern observed in WhatsApp (×20.6) and TikTok (×286), where nested FragmentManager state multiplies the original payload size at each level.


4. Connection to AndroidX PdfView Commit

On 14 July 2026, a commit was merged into AndroidX (8882927e7d41e678c6f03f50d4bd5950e7dc6c47) that fixes a TransactionTooLargeException in PdfView. The commit message states:

“When a user selects content across a large range of pages (e.g., 500 pages), the serialized SelectionModel exceeds 1.2 MB. Serializing this into onSaveInstanceState triggers an unhandled TransactionTooLargeException over the kernel Binder IPC driver right when the app goes into the background.”

The fix was to change the persistent representation: rather than serialising the full SelectionModel, only anchor points (~44 bytes) are saved, and the full state is reconstructed asynchronously upon restoration.

Note: This commit is independent of the STA research, but it confirms that Google is actively mitigating the same general class of oversized‑state / Binder‑boundary problems in components related to document handling and print preview.

However, the commit is scoped to androidx.pdf.viewer.PdfView only. It does not address the Print Service, SystemUI, or TaskPersister paths documented in STA-009, STA-010, and STA-018. As of September 2026, those paths remain publicly unpatched.


5. Relation to Other STA Vectors

VectorConnection
STA-015-DL Similar chain (Google Drive HTML → browser ANR → SystemUI crash loop), but triggered via a web link rather than the print UI. Both share the TaskPersister corruption mechanism.
STA-005 Class A amplification through FragmentManager / SavedState, but in the context of messaging apps (WhatsApp) rather than printing. The underlying cause — oversized Bundle → Binder → uncaught exception — is identical.
STA-012 Threads deep-link crash. Also Class A, also involves a structured payload crossing Binder without validation.
STA-017 Class B (libminikin ANR) — unrelated to printing, but shares the same root‑cause pattern: missing size validation before an expensive operation (text layout in libminikin; Binder serialisation in Print Service).

The Print Preview vectors are a clear demonstration that the STA pattern is not confined to a single application or component. It recurs across document handling, messaging, and system UI — all tied to the same underlying architectural gap: structured input → serialization → Binder → uncaught exception → crash.


6. Mitigation Recommendations

6.1. Framework (AOSP / AndroidX)

  • Validate Bundle size before serialization in PrintManager and PrintService — reject or truncate if the 1 MB limit is approached.
  • Catch TransactionTooLargeException in both the Print Service and SystemUI, and degrade gracefully (show an error message instead of crashing).
  • Adopt LargePayloadSupport (FD‑based transfer) for print previews, similar to what already exists for Credential Manager and Digital Credentials.
  • Prevent TaskPersister corruption by validating restored state size before persisting it to disk.

6.2. Application-level (Google Drive, document viewers)

  • Truncate document content before passing it to the Print Service — limit the number of pages, reduce preview resolution, or cap text length to 50,000 characters.
  • Reject print intents that contain oversized documents (e.g., by checking the document size before calling PrintManager.print()).

6.3. OEM-specific (HyperOS, One UI, ColorOS)

  • OEMs should apply safe degradation patterns in their Task State Interactors, similar to the pattern proposed in Section 16.4 of the STA whitepaper (catch DeadObjectException and emit null instead of crashing).

7. Conclusion

The Print Preview vector is a clear and well-documented manifestation of Class A Structured Text Amplification in a system‑level service (Print Service / SystemUI). It demonstrates that the same architectural pattern — structured input → serialization → Binder → uncaught exception → crash — recurs across multiple surfaces, from messaging apps to document handling to system UI.

The independent AndroidX fix for PdfView confirms that Google is aware of this class of problems, but the Print Service and SystemUI paths remain unpatched as of September 2026. Organisations relying on Android for document workflows should consider implementing defensive truncation at the application level.

This vector also reinforces the broader STA thesis: the problem is not a single bug, but a systemic architectural gap that requires a coordinated, cross‑component response from the Android framework.


8. Related Publications


STA-006 / 007 Translate: When translating text crashes Google Apps

Wednesday, August 26, 2026

STA-006 / 007 Translate: When translating text crashes Google Apps

Structured Text Amplification — Vectors 006 & 007

This post documents STA-006 and STA-007, two denial-of-service vectors in Google's Translate feature. An oversized text payload, when selected and sent to Translate via Intent.ACTION_TRANSLATE, can exceed the Binder transaction limit, causing a TransactionTooLargeException and a permanent crash loop in some cases.

⚠️ Severity: STA-006 and STA-007 are persistent DoS vectors in some oems implementations. A single oversized text selection can make Google App or Google Drive permanently unusable until the user clears app data. No special permissions or privileges are required.


1. Overview

STA-006 and STA-007 describe a persistent denial-of-service condition in Google's Translate feature, accessible from multiple Google apps. An attacker can craft or deliver an oversized text payload that, when selected and translated, contaminates the app's state and causes a permanent crash loop in oems.

The vector is triggered when the user selects a large text (visible or hidden) and invokes the Translate action. The app constructs an Intent.ACTION_TRANSLATE containing the selected text. During serialization of the Intent for transfer via Binder, the data size may exceed the Binder transaction limit (approximately 1 MiB). This can result in an unhandled TransactionTooLargeException, causing an immediate app crash.

Type: semi-persistent Denial of Service (DoS)
Class: Resource Exhaustion / State Persistence Boundary
CWE: CWE-400 — Uncontrolled Resource Consumption; CWE-770 — Allocation of Resources Without Limits
CVSS v3.1 estimated: 6.5 (Medium-High)
Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H


2. Attack chain

The observed chain can be represented as:

Attacker crafts/places oversized text payload
       ↓
User selects the text (or selects all in a PDF)
       ↓
User invokes Translate action (context menu or app button)
       ↓
Google App / Google Drive constructs ACTION_TRANSLATE Intent
       ↓
Selected text stored in Intent extra (EXTRA_TEXT)
       ↓
Intent serialization (Parcel)
       ↓
Parcel size exceeds Binder limit (1 MB)
       ↓
TransactionTooLargeException
       ↓
App crashes immediately
       ↓
State may be re-persisted (in Google Drive)
       ↓
App crashes on every launch attempt (persistent crash loop)
       ↓
Recovery: clear app data or uninstall/reinstall

The fundamental characteristic of STA-006/007 is that the STA payload is delivered through a standard user action (Translate) that the app is designed to handle. The user does nothing unusual — just selects text and translates it.


3. Vector details

3.1. STA-006 — Google App (Select text → Translate)

The vector is triggered through the Google App's selection menu:

  • The user selects a large text (e.g., from a web page, document, or any text field).
  • The user taps the "Translate" action from the context menu.
  • Google App creates an ACTION_TRANSLATE Intent with the selected text as EXTRA_TEXT.
  • During serialization of the Intent, the Bundle size exceeds the Binder transaction limit.
  • TransactionTooLargeException is thrown and not caught.
  • Google App crashes immediately.

Entry point: android.app.Activity.startActivityForResult() → Instrumentation.execStartActivity() → Binder transaction → TransactionTooLargeException

3.2. STA-007 — Google Drive (PDF → Select All → Translate)

The vector is triggered through Google Drive's PDF viewer:

  • User opens a PDF containing invisible or oversized text (e.g., a PDF with a large hidden payload).
  • User selects all text (Select All) in the PDF viewer.
  • User taps the "Translate" action from the selection menu.
  • Google Drive creates an ACTION_TRANSLATE Intent with the selected text.
  • During serialization of the Intent, the Bundle size exceeds the Binder transaction limit.
  • TransactionTooLargeException is thrown and not caught.
  • Google Drive crashes immediately.
  • If the state is re-persisted, the app enters a permanent crash loop.

Entry point: PDF viewer selection menu → Intent.ACTION_TRANSLATE → Binder transaction → TransactionTooLargeException


4. Stack trace and Bundle analysis

The following stack trace and Bundle statistics were captured from a production device (Xiaomi Redmi Note 14 5G, HyperOS 3.0, Android 16) during a crash of the Google App. The crash occurred after selecting an oversized text payload, invoking Translate, and subsequently focusing the search bar, which triggered the state serialization and Binder transaction.

4.1. Exception

java.lang.RuntimeException: android.os.TransactionTooLargeException:
data parcel size 2454260 bytes
    at android.app.servertransaction.PendingTransactionActions$StopInfo.run(PendingTransactionActions.java:146)
    at android.os.Handler.handleCallback(Handler.java:1029)
    at android.os.Handler.dispatchMessage(Handler.java:107)
    at android.os.Looper.loopOnce(Looper.java:274)
    at android.os.Looper.loop(Looper.java:369)
    at android.app.ActivityThread.main(ActivityThread.java:10090)
    at java.lang.reflect.Method.invoke(Native Method)
    at com.android.internal.os.RuntimeInit$MethodAndArgsCaller.run(RuntimeInit.java:616)
    at com.android.internal.os.ZygoteInit.main(ZygoteInit.java:1137)
Caused by:
android.os.TransactionTooLargeException:
data parcel size 2454260 bytes
    at android.os.BinderProxy.transactNative(Native Method)
    at android.os.BinderProxy.transact(BinderProxy.java:736)
    at android.app.IActivityClientController$Stub$Proxy.activityStopped(IActivityClientController.java:1546)
    at android.app.ActivityClient.activityStopped(ActivityClient.java:106)
    at android.app.servertransaction.PendingTransactionActions$StopInfo.run(PendingTransactionActions.java:135)

4.2. Bundle statistics

The Bundle that triggered the exception contained the following components:

Bundle stats:
    androidx.lifecycle.BundlableSavedStateRegistry.key [size=2452080]
    androidx.lifecycle.internal.SavedStateHandlesProvider [size=1127400]
    tt_activity_account_retained:6 [size=1125236]
    SearchSession:1 [size=1125012]
    androidx.lifecycle.BundlableSavedStateRegistry.key [size=1124884]
    androidx.lifecycle.internal.SavedStateHandlesProvider [size=1124752]
    androidx.lifecycle.ViewModelProvider.DefaultKey:... [size=1124452]
    BrowserSession:2 [size=963088]
    androidx.lifecycle.BundlableSavedStateRegistry.key [size=962960]
    androidx.lifecycle.internal.SavedStateHandlesProvider [size=962828]
    webx_browser [size=962464]
    webx_window [size=962416]
    web_view_url [size=962288]
    search_query_key [size=161080]
    search_query [size=161028]
    protoparsers [size=160976]
    android:support:fragments [size=1312836]
    fragment_e32da9b3... [size=1312412]
    arguments [size=161152]
    TIKTOK_FRAGMENT_ARGUMENT [size=161008]
    childFragmentManager [size=1312836]
    android-support-nav:controller:backStack [size=326252]
    registryState [size=168492]
    SEARCH_QUERY_STATE [size=160976]
    ... (additional nested fragment states)

4.4. Key metrics

Component Size
Input (search_query) ~161,028 bytes
childFragmentManager 1,312,836 bytes
SavedStateHandlesProvider 1,127,400 bytes
SearchSession / BrowserSession ~1,125,000 bytes each
Total Bundle size 2,454,260 bytes
Binder transaction limit 1,048,576 bytes
Excess +1,405,684 bytes (+134%)
Amplification factor ×15.2

Key observation: The input payload (~161 KB) is amplified to a total Bundle size of 2.45 MB through the serialization of nested Fragment states, SavedState handles, and session data. The amplification factor of ×15.2 is consistent with the amplification patterns documented in other Class A vectors (STA-005, ×20.6; STA-012, ×20.6).


5. Affected components

Primary

  • android.content.Intent — ACTION_TRANSLATE intent extra serialization
  • android.os.Bundle — serialization container
  • android.os.Parcel — Binder serialization
  • android.app.ActivityThread — lifecycle handling
  • androidx.fragment.app.FragmentManager — fragment state serialization
  • androidx.lifecycle.SavedStateHandlesProvider — SavedState management

Secondary

  • android.app.ActivityManagerProxy — Binder transaction
  • Google App (com.google.android.googlequicksearchbox) — Translate feature
  • Google Drive (com.google.android.apps.docs) — PDF viewer + Translate feature

6. Persistence

Persistence: YES (STA-007), Conditional (STA-006)

  • STA-006 (Google App): The app may crash immediately, but the state is not always re-persisted. Recovery typically involves reopening the app.
  • STA-007 (Google Drive): The PDF viewer state is saved, and the oversized payload may be re-persisted, causing a crash on every launch.

Recovery typically requires:

  • Clearing the app data (via adb pm clear com.google.android.googlequicksearchbox or adb pm clear com.google.android.apps.docs)
  • Uninstalling and reinstalling the app (loses all data)

7. Why this matters

STA-006 and STA-007 are not just crashes. They are semi-persistent denial-of-service vectors with significant implications:

  • For individual users: They lose access to the app until they clear data, losing all settings and potentially documents.
  • For Google: A single malicious document can make Google Drive unusable for any user who opens it and attempts to translate.
  • For the platform: This is a single point of failure in the Intent serialization and Binder transaction mechanism.

The vector is particularly concerning because:

  • The payload can be delivered through a standard PDF document that the app is designed to handle.
  • No special permissions are required.
  • The user does nothing unusual — just selects text and translates it.
  • The impact is persistent in some OEMS and requires clearing data to recover.

8. Relationship to other STA vectors

Vector Relationship
STA-003 Same mechanism (Share Intent → Binder → TransactionTooLargeException)
STA-005 Same mechanism (text input → SavedState → Bundle → Binder → crash loop). WhatsApp has a similar amplification factor (×20.6).
STA-012 Same mechanism (deep link → Fragment args → SavedState → Binder → crash loop)
STA-028 UTF-16 encoding amplification is a contributing factor to the measured amplification.

9. Chromium commit evidence

Chromium commit 84b615a0 (5 May 2026) added the Translate action to the Android PDF viewer's selection menu, confirming that this surface is considered relevant and that Google engineers have been working on it. The commit introduced:

84b615a07fc14988b46f0e362502ab4075216793
Author: Ryan Thomas
Date: 5 May 2026
Component: Android PDF viewer selection menu
Changes: Added Share, Web Search, Translate actions to selection menu

This demonstrates that the surface identified by STA-006/007 is being actively developed and modified, further validating the architectural relevance of the findings.


10. Recommended mitigation

10.1. Application-level (Google App / Google Drive)

  • Validate the size of selected text before constructing the ACTION_TRANSLATE Intent.
  • Truncate text to a safe limit (e.g., 8 KB) before placing it in EXTRA_TEXT.
  • Catch TransactionTooLargeException and fall back to a clean state.
// Recommended approach for Translate action
String selectedText = getSelectedText();
if (selectedText != null && selectedText.length() > MAX_SAFE_LENGTH) {
    selectedText = selectedText.substring(0, MAX_SAFE_LENGTH);
    Log.w(TAG, "Selected text truncated to safe length");
}
Intent translateIntent = new Intent(Intent.ACTION_TRANSLATE);
translateIntent.putExtra(Intent.EXTRA_TEXT, selectedText);
try {
    startActivity(translateIntent);
} catch (TransactionTooLargeException e) {
    Log.e(TAG, "Translate Intent too large", e);
    // Fallback: show error dialog or use alternative translation method
}

10.2. Framework-level (Android)

  • Intent serialization should include a size estimation before Binder transaction.
  • SystemUI should catch TransactionTooLargeException and handle it gracefully.
  • FragmentManager should limit the size of saved state before serialization.

11. Research status

Field Value
Vectors STA-006, STA-007
First formal communication 20 January 2026
Researcher Manuel García Peña (Lostmon)
Nature Independent research
Platform Android
Impact Persistent DoS
Interaction required Yes (one click / selection)
Privileges None
Tier A (Confirmed — full stack trace + exception)

STA-006/007 are part of the broader Structured Text Amplification (STA) research, which studies a recurring pattern of resource exhaustion produced when input data crosses serialization, transformation, IPC, or persistence boundaries without sufficiently early resource limits.


12. Conclusion

STA-006 and STA-007 demonstrate how a standard Translate action can become a persistent denial-of-service vector when the app fails to validate the size of selected text before constructing an Intent.

The amplification mechanism is consistent with other Class A vectors, confirming that the problem is architectural rather than specific to a single app:

Selected text (~161 KB)
 → Intent (ACTION_TRANSLATE)
 → FragmentManager serialization
 → SavedStateHandlesProvider
 → Bundle (2.45 MB)
 → Parcel
 → Binder
 → TransactionTooLargeException
 → Persistent crash loop

The most robust mitigation is to validate input size before constructing the Intent, complemented by fallback mechanisms that prevent an oversize condition from becoming a persistent crash loop.


Complete whitepaper: Resilience Gaps in Android IPC, SavedState and Text Layout — v6 (August 2026)


📌 About this series
This post is part of a series documenting the 32 vectors of Structured Text Amplification (STA).

Published:
✅ STA-017 — Cross-Engine ANR
✅ STA-015-DL — Google Drive → SystemUI
✅ STA-005 — WhatsApp
✅ STA-003 — Binder Share Intent
✅ STA-006/007 — Translate (this post)

Coming next:
⬜ STA-012 — Threads
⬜ STA-019 — Firefox
⬜ STA-022 — DuckDuckGo

Whitepaper: Resilience Gaps in Android IPC, SavedState and Text Layout — v6


— Lostmon · lostmon.blogspot.com

 

Browse

About:Me

My blog:http://lostmon.blogspot.com
Mail:Lostmon@gmail.com
Lostmon Google group
Lostmon@googlegroups.com

La curiosidad es lo que hace
mover la mente...

Friends