Mitigate Intent Capturing vulnerability
ResolverActivity now identifies that the intent is a browsable intent, and thus omits the Always button and replaces it with a settings button tha can be used to configure the user's wanted behaviour. Also prints out a message explaining that the user is giving the app an access to open URLs from a specific host. Bug: 116610086 Test: manually tested on device (Pixel 2XL) - will add unit test to document behaviour Change-Id: I81988b9a4d082bc1e6491186d39532fd283f2ede
Loading
Please register or sign in to comment