diff options
| author | 2025-01-02 14:58:50 -0800 | |
|---|---|---|
| committer | 2025-01-03 16:02:09 -0800 | |
| commit | 7f08bd21cb8675be4504690b635cc6727d620f18 (patch) | |
| tree | 923c6123c2dbbe635e5e43ecae8080f0557b89fd /libs/androidfw/StringPool.cpp | |
| parent | 39e7bb09fcd4d0c1efa49cf4476fc3254ec53750 (diff) | |
Resolve cross account user icon validation.
Resolves a vulnerability found with the cross account user icon
validation in StatusHint and TelecomServiceImpl (when registering a
phone account). The reporter found that an uri formatted as `userId%`
isn't parsed properly with the existing reference to Uri.encodedUserInfo.
Bug: 376461551
Bug: 376259166
Flag: EXEMPT bugfix
Test: atest TelecomServiceImplTest
Change-Id: I25614ead889501f4553ed2b42b366e09a47b0c9f
Merged-In: I25614ead889501f4553ed2b42b366e09a47b0c9f
Diffstat (limited to 'libs/androidfw/StringPool.cpp')
0 files changed, 0 insertions, 0 deletions