Resolve cross account user ringtone validation.
Resolves a vulnerability found with the lack of cross account user ringtone validation in RingtoneFactory. The reporter found that a ringtone file owned by a different user can be accessed and played by the user who does not own that file. Bug: 356604577 Flag: EXEMPT Critical CVE bugfix Test: RingtoneFactoryTest (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:1c7fbd70da65f7b2dd561af8ec9f94b81acf5baa) (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:5c1c52a95703b14ba2921a4d08abeb1ec592e82a) Merged-In: Ie28e8d0890086caada561ed27dd660836e6aa6bb Change-Id: Ie28e8d0890086caada561ed27dd660836e6aa6bb
Loading
Please register or sign in to comment