Merge "Fix html injection in Autofill confirmation dialog" into tm-qpr-dev am: ecb7c54fc5

Original change: https://googleplex-android-review.googlesource.com/c/platform/packages/apps/Settings/+/20904550

Change-Id: I4e713518a4f0de69a4d85514315048d438b53fb3
Signed-off-by: Automerger Merge Worker <android-build-automerger-merge-worker@system.gserviceaccount.com>
diff --git a/src/com/android/settings/applications/defaultapps/DefaultAutofillPicker.java b/src/com/android/settings/applications/defaultapps/DefaultAutofillPicker.java
index f1e7ac0..d96aa6b 100644
--- a/src/com/android/settings/applications/defaultapps/DefaultAutofillPicker.java
+++ b/src/com/android/settings/applications/defaultapps/DefaultAutofillPicker.java
@@ -243,7 +243,7 @@
         }
         final CharSequence appName = appInfo.loadLabel();
         final String message = getContext().getString(
-                R.string.autofill_confirmation_message, appName);
+                R.string.autofill_confirmation_message, Html.escapeHtml(appName));
         return Html.fromHtml(message);
     }