Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 992cfbf6 authored by TreeHugger Robot's avatar TreeHugger Robot Committed by Android (Google) Code Review
Browse files

Merge "Address SessionCommitReceiver vulnerability by validating intent." into...

Merge "Address SessionCommitReceiver vulnerability by validating intent." into ub-launcher3-qt-future-dev
parents 45656e29 7e04887e
Loading
Loading
Loading
Loading
+6 −1
Original line number Diff line number Diff line
@@ -71,8 +71,13 @@ public class SessionCommitReceiver extends BroadcastReceiver {

        SessionInfo info = intent.getParcelableExtra(PackageInstaller.EXTRA_SESSION);
        UserHandle user = intent.getParcelableExtra(Intent.EXTRA_USER);
        PackageInstallerCompat packageInstallerCompat = PackageInstallerCompat.getInstance(context);
        if (!PackageInstaller.ACTION_SESSION_COMMITTED.equals(intent.getAction())
                || info == null || user == null) {
            // Invalid intent.
            return;
        }

        PackageInstallerCompat packageInstallerCompat = PackageInstallerCompat.getInstance(context);
        if (TextUtils.isEmpty(info.getAppPackageName())
                || info.getInstallReason() != PackageManager.INSTALL_REASON_USER
                || packageInstallerCompat.promiseIconAddedForId(info.getSessionId())) {