summaryrefslogtreecommitdiff
path: root/libs/androidfw/StringPool.cpp
diff options
context:
space:
mode:
author Pranav Madapurmath <pmadapurmath@google.com> 2025-01-02 14:58:50 -0800
committer Pranav Madapurmath <pmadapurmath@google.com> 2025-01-03 16:02:09 -0800
commit7f08bd21cb8675be4504690b635cc6727d620f18 (patch)
tree923c6123c2dbbe635e5e43ecae8080f0557b89fd /libs/androidfw/StringPool.cpp
parent39e7bb09fcd4d0c1efa49cf4476fc3254ec53750 (diff)
Resolve cross account user icon validation.
Resolves a vulnerability found with the cross account user icon validation in StatusHint and TelecomServiceImpl (when registering a phone account). The reporter found that an uri formatted as `userId%` isn't parsed properly with the existing reference to Uri.encodedUserInfo. Bug: 376461551 Bug: 376259166 Flag: EXEMPT bugfix Test: atest TelecomServiceImplTest Change-Id: I25614ead889501f4553ed2b42b366e09a47b0c9f Merged-In: I25614ead889501f4553ed2b42b366e09a47b0c9f
Diffstat (limited to 'libs/androidfw/StringPool.cpp')
0 files changed, 0 insertions, 0 deletions