commit | 71a03fd10e222b6ed5f540f8cc5272a73bd85a57 | [log] [tgz] |
---|---|---|
author | Pranav Madapurmath <pmadapurmath@google.com> | Thu Jan 02 14:58:50 2025 -0800 |
committer | Android Build Coastguard Worker <android-build-coastguard-worker@google.com> | Thu Jan 09 12:29:52 2025 -0800 |
tree | a26b37026361b277af6f0751f5d617c85ea0f62f | |
parent | 1c52a852d8b8d6fa4dd3a0ef9bab631eff0332bd [diff] |
Resolve cross account user icon validation. Resolves a vulnerability found with the cross account user icon validation in StatusHint and TelecomServiceImpl (when registering a phone account). The reporter found that an uri formatted as `userId%` isn't parsed properly with the existing reference to Uri.encodedUserInfo. Bug: 376461551 Bug: 376259166 Flag: EXEMPT bugfix Test: atest TelecomServiceImplTest (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:81c9a17787743df280adac58ab5f74c084d058e1) Merged-In: I25614ead889501f4553ed2b42b366e09a47b0c9f Change-Id: I25614ead889501f4553ed2b42b366e09a47b0c9f