+111
−0
Loading
Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more
Resolves a vulnerability found with the lack of cross account user ringtone validation in RingtoneFactory. The reporter found that a ringtone file owned by a different user can be accessed and played by the user who does not own that file. This fix also prevents a regression that was caused by the original fix for this issue. Bug: 356604577 Flag: EXEMPT Critical CVE bugfix Test: RingtoneFactoryTest Change-Id: I8687470f3be2f68f10cc20f684f401ef4bd9357b