Prevent exfiltration of system files via user image settings.
This is a backport of ag/17005706. This adds mitigations to prevent system files being exfiltrated via the settings content provider when a content URI is provided as a chosen user image. The mitigations are: 1) Copy the image to a new URI rather than the existing takePictureUri prior to cropping. 2) Only allow a system handler to respond to the CROP intent. Bug: 187702830 Test: build and check functionality Change-Id: Ia6314b6810afb5efa0329f3eeaee9ccfff791966 Merged-In: I15e15ad88b768a5b679de32c5429d921d850a3cb (cherry picked from commit 8950a900) Merged-In: Ia6314b6810afb5efa0329f3eeaee9ccfff791966
Loading
Please register or sign in to comment