74b03835a7fac15e854d08159922418c99e27e77 - platform/frameworks/base - Git at Google (original) (raw)
android / platform / frameworks / base / 74b03835a7fac15e854d08159922418c99e27e77
commit | 74b03835a7fac15e854d08159922418c99e27e77 | [log] [tgz] |
---|---|---|
author | kumarashishg kumarashishg@google.com | Mon Jul 17 12:01:18 2023 +0000 |
committer | Android Build Coastguard Worker android-build-coastguard-worker@google.com | Thu Jan 11 04:45:53 2024 +0000 |
tree | 09a84ab18a051fc74c8fe26b9bfd2bdb300176a3 | |
parent | 3b7fa771d7156f2eef4b4eb0d3f5054d416ca3ea [diff] |
Resolve custom printer icon boundary exploit.
Because Settings grants the INTERACT_ACROSS_USERS_FULL permission, an exploit is possible where the third party print plugin service can pass other's User Icon URI. This CL provides a lightweight solution for parsing the image URI to detect profile exploitation.
Bug: 281525042 Test: Build and flash the code. Try to reproduce the issue with mentioned steps in the bug (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:0e0693ca9cb408d0dc82f6c6b3feb453fc8ddd83) Merged-In: Iaaa6fe2a627a265c4d1d7b843a033a132e1fe2ce Change-Id: Iaaa6fe2a627a265c4d1d7b843a033a132e1fe2ce
1 file changed
tree: 09a84ab18a051fc74c8fe26b9bfd2bdb300176a3
- .prebuilt_info/
- apct-tests/
- apex/
- api/
- boot/
- cmds/
- config/
- core/
- data/
- docs/
- drm/
- errorprone/
- graphics/
- identity/
- keystore/
- libs/
- location/
- lowpan/
- media/
- mime/
- mms/
- native/
- nfc-extras/
- obex/
- opengl/
- packages/
- proto/
- rs/
- samples/
- sax/
- services/
- startop/
- telecomm/
- telephony/
- test-base/
- test-legacy/
- test-mock/
- test-runner/
- tests/
- tools/
- wifi/
- .clang-format
- .gitignore
- .mailmap
- Android.bp
- Android.mk
- ApiDocs.bp
- BATTERY_STATS_OWNERS
- CleanSpec.mk
- framework-jarjar-rules.txt
- METADATA
- MODULE_LICENSE_APACHE2
- MULTIUSER_OWNERS
- NOTICE
- OWNERS
- OWNERS.md
- pathmap.mk
- PREUPLOAD.cfg
- ProtoLibraries.bp
- StubLibraries.bp
- TEST_MAPPING
- TestProtoLibraries.bp
- ZYGOTE_OWNERS