Fix for SAF loophole in the lastAccessedStack.
When loading the last accessed stack, the code did not check if the file path (uri) should be blocked, thereby allowing an attacker to bypass the scoped storage restriction put on initial uri. This change adds the check when loading last accessed stack. Bug: 352294617 Test: Manual as per http://b/352294617#comment4 Flag: EXEMPT bugfix (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:30596588b508f1e5e97631470af479214898064a) Merged-In: I4de8bad7174273c9390da978e186ad6a85f27be5 Change-Id: I4de8bad7174273c9390da978e186ad6a85f27be5
Loading
Please register or sign in to comment