Fix security vulnerability when register phone accounts.
Currently if the registered self-managed phone account updated to a call provider phone account, the enable state will be directly copied to the updated one so that malicious app can perform call spoofing attack without any permission requirements. Fix this by disallowing change a self-managed phone account to a managed phone account. Bug: 246930197 Test: CtsTelecomTestCases:SelfManagedConnectionSreviceTest Change-Id: I8f7984cd491632b3219133044438b82ca4dec80e Merged-In: I8f7984cd491632b3219133044438b82ca4dec80e
Loading
-
mentioned in commit 581e2232
-
mentioned in commit a0d27810
-
mentioned in commit 275debd2
-
mentioned in commit cf69b113
-
mentioned in commit cc6243dc
-
mentioned in commit ddce3b0c
-
mentioned in commit e3413b45
-
mentioned in commit 3542bd1a
-
mentioned in commit dcf20ea0
-
mentioned in commit b0800084
Please register or sign in to comment