Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit a604311f authored by Pranav Madapurmath's avatar Pranav Madapurmath
Browse files

Resolve account image icon profile boundary exploit.

Because Telecom grants the INTERACT_ACROSS_USERS permission, an exploit
is possible where the user can upload an image icon (belonging to
another user) via registering a phone account. This CL provides a
lightweight solution for parsing the image URI to detect profile
exploitation.

Fixes: 273502295
Fixes: 296915211
Test: Unit test to enforce successful/failure path
Change-Id: I2b6418f019a373ee9f02ba8683e5b694e7ab80a5
(cherry picked from commit d0d1d38e)
Merged-In: I2b6418f019a373ee9f02ba8683e5b694e7ab80a5
(cherry picked from commit e7d0ca3f)
parent 29b52e3c
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment