commit | 4ab4d3dd02671d3e36d83a8de1288364ed576d04 | [log] [tgz] |
---|---|---|
author | Pranav Madapurmath <pmadapurmath@google.com> | Thu Jan 02 15:04:45 2025 -0800 |
committer | Android Build Coastguard Worker <android-build-coastguard-worker@google.com> | Mon Jan 13 11:46:03 2025 -0800 |
tree | d658c9a111e72934565bcea8a2eda6f1cbcbfe66 | |
parent | 2977b43aaeb56140e19b2fb06cb7fd97d101018f [diff] |
Resolve cross account user icon validation. Resolves a vulnerability found with the cross account user icon validation in StatusHint and TelecomServiceImpl (when registering a phone account). The reporter found that an uri formatted as `userId%` isn't parsed properly with the existing reference to Uri.encodedUserInfo. Bug: 376461551 Bug: 376259166 Flag: EXEMPT bugfix Test: atest TelecomServiceImplTest (cherry picked from https://googleplex-android-review.googlesource.com/q/commit:5f1be4f4b02ded791ad72725c4eef44287b08b1b) Merged-In: I7a5f64ae01eaf6a133ea04c51bd00dbe1653b74f Change-Id: I7a5f64ae01eaf6a133ea04c51bd00dbe1653b74f