Skip to content
Snippets Groups Projects
  1. Aug 03, 2023
  2. Aug 02, 2023
  3. Aug 01, 2023
    • Anton Potapov's avatar
      Add userId check before loading icon in Device Controls · 331f2f1b
      Anton Potapov authored
      Test: manual with the steps from the bug
      Test: manual with a normal icon
      Test: atest CanUseIconPredicate
      Test: atest ControlViewHolderTest
      Bug: 272025416
      (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:ffa97f42dd9496bb404e01727c923292d05a4466)
      Merged-In: I39b7bc62d82e20b5ba8747be13a2aa7bf21a59a2
      Merged-In: I60896a6f53307f0e97a9223b599a2891c6c0c08d
      Merged-In: Ib0e677f7ccbed6299ea07939519c7dcf6d371bec
      Merged-In: Ibe4fb69a90904787b9f97a7cd90d318a047d1e11
      Merged-In: Iba846f19098c71c0519470cd7b8c1fd60d47e70b
      Change-Id: I354469a53611c094c7bb695b1c2017c6786dd396
      331f2f1b
    • Anton Potapov's avatar
      Add userId check before loading icon in Device Controls · 22f18e02
      Anton Potapov authored
      Test: manual with the steps from the bug
      Test: manual with a normal icon
      Test: atest CanUseIconPredicate
      Test: atest ControlViewHolderTest
      Bug: 272025416
      Merged-In: I39b7bc62d82e20b5ba8747be13a2aa7bf21a59a2
      Merged-In: I60896a6f53307f0e97a9223b599a2891c6c0c08d
      Merged-In: Ib0e677f7ccbed6299ea07939519c7dcf6d371bec
      Merged-In: Ibe4fb69a90904787b9f97a7cd90d318a047d1e11
      Change-Id: Iba846f19098c71c0519470cd7b8c1fd60d47e70b
      22f18e02
  4. Jul 31, 2023
  5. Jul 27, 2023
  6. Jul 26, 2023
  7. Jul 18, 2023
    • kumarashishg's avatar
      Resolve custom printer icon boundary exploit. · 0e0693ca
      kumarashishg authored
      Because Settings grants the INTERACT_ACROSS_USERS_FULL permission, an exploit is possible where the third party print plugin service can pass other's User Icon URI. This CL provides a lightweight solution for parsing the image URI to detect profile exploitation.
      
      Bug: 281525042
      Test: Build and flash the code. Try to reproduce the issue with
      mentioned steps in the bug
      
      Change-Id: Iaaa6fe2a627a265c4d1d7b843a033a132e1fe2ce
      Merged-In: Iaaa6fe2a627a265c4d1d7b843a033a132e1fe2ce
      0e0693ca
    • kumarashishg's avatar
      Resolve custom printer icon boundary exploit. · 658ed370
      kumarashishg authored
      Because Settings grants the INTERACT_ACROSS_USERS_FULL permission, an exploit is possible where the third party print plugin service can pass other's User Icon URI. This CL provides a lightweight solution for parsing the image URI to detect profile exploitation.
      
      Bug: 281525042
      Test: Build and flash the code. Try to reproduce the issue with
      mentioned steps in the bug
      
      Change-Id: Iaaa6fe2a627a265c4d1d7b843a033a132e1fe2ce
      Merged-In: Iaaa6fe2a627a265c4d1d7b843a033a132e1fe2ce
      658ed370
    • kumarashishg's avatar
      Resolve custom printer icon boundary exploit. · 9adc7202
      kumarashishg authored
      Because Settings grants the INTERACT_ACROSS_USERS_FULL permission, an exploit is possible where the third party print plugin service can pass other's User Icon URI. This CL provides a lightweight solution for parsing the image URI to detect profile exploitation.
      
      Bug: 281525042
      Test: Build and flash the code. Try to reproduce the issue with
      mentioned steps in the bug
      
      Change-Id: Iaaa6fe2a627a265c4d1d7b843a033a132e1fe2ce
      Merged-In: Iaaa6fe2a627a265c4d1d7b843a033a132e1fe2ce
      9adc7202
  8. Jul 13, 2023
  9. Jul 12, 2023
  10. Jul 10, 2023
Loading