Resolve cross-user image exploit for conference status hints
Ensure that status hint image icon is validated for cross-user exploits. Currently, there is no check for this so a conference call can display an image from another user, exposing a vulnerability. Bug: 329058967 Test: Manual with POC (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:8c619f58c00047ab0ec687cd231bf93a08db6d55) Merged-In: Ib9d701398d25d021cdb9abacbaa5b175f62bee1d Change-Id: Ib9d701398d25d021cdb9abacbaa5b175f62bee1d
Loading
Please register or sign in to comment