Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit e94b6b90 authored by Kunal Malhotra's avatar Kunal Malhotra
Browse files

Checking if package belongs to UID before registering broadcast receiver

Test: manual testing done on device by installing test APK and checking if receiver can register
Bug: 242040055
Change-Id: Ia525f218a46f8bf7fff660cec0d6432f09fdf24d
Merged-In: Ia525f218a46f8bf7fff660cec0d6432f09fdf24d
(cherry picked from commit 790a8d0d)
parent c023c97f
Loading
Loading
Loading
Loading
+5 −0
Original line number Diff line number Diff line
@@ -3420,6 +3420,11 @@ public final class ActiveServices {
                            throw new SecurityException("BIND_EXTERNAL_SERVICE failed, "
                                    + className + " is not an isolatedProcess");
                        }
                        if (!mAm.getPackageManagerInternal().isSameApp(callingPackage, callingUid,
                                userId)) {
                            throw new SecurityException("BIND_EXTERNAL_SERVICE failed, "
                                    + "calling package not owned by calling UID ");
                        }
                        // Run the service under the calling package's application.
                        ApplicationInfo aInfo = AppGlobals.getPackageManager().getApplicationInfo(
                                callingPackage, ActivityManagerService.STOCK_PM_FLAGS, userId);