[DO NOT MERGE] Don't allow permission change to runtime
Prevent apps to change permission protection level to dangerous from any other type as this would allow a privilege escalation where an app adds a normal permission in other app's group and then redefines it as dangerous leading to the group auto-grant. Test: Added a CTS test which passes. Bug: 33860747 AOSP-Change-Id: I1ccf546f78ee79ff027cb98124be81c8e5265a82 (cherry picked from commit fe430be9) CVE-2017-0593 Change-Id: I6878332b5c4a38225efa8fc7ffa4b868b6b2917d
Loading
Please register or sign in to comment