summaryrefslogtreecommitdiff
path: root/libs/androidfw/ResourceTimer.cpp
diff options
context:
space:
mode:
author kumarashishg <kumarashishg@google.com> 2023-07-17 12:01:18 +0000
committer Ashish Kumar Gupta <kumarashishg@google.com> 2023-07-18 15:28:03 +0000
commit0e0693ca9cb408d0dc82f6c6b3feb453fc8ddd83 (patch)
tree2956f400e585a19ce73800ddfcca5a03e594871f /libs/androidfw/ResourceTimer.cpp
parente6f4326547a17aafaac2c9744aa3f91869d70ebf (diff)
Resolve custom printer icon boundary exploit.
Because Settings grants the INTERACT_ACROSS_USERS_FULL permission, an exploit is possible where the third party print plugin service can pass other's User Icon URI. This CL provides a lightweight solution for parsing the image URI to detect profile exploitation. Bug: 281525042 Test: Build and flash the code. Try to reproduce the issue with mentioned steps in the bug Change-Id: Iaaa6fe2a627a265c4d1d7b843a033a132e1fe2ce Merged-In: Iaaa6fe2a627a265c4d1d7b843a033a132e1fe2ce
Diffstat (limited to 'libs/androidfw/ResourceTimer.cpp')
0 files changed, 0 insertions, 0 deletions