Make mutable PendingIntent explicit
Starting from target SDK U, we will block creation of mutable PendingIntents with implicit Intents because attackers can mutate the Intent object within and launch altered behavior on behalf of victim apps. For more details on the vulnerability, see go/pendingintent-rca. From a quick analysis, we concluded that the PendingIntent here was only destined to the test app/to the app, so it was made explicit. Reviewers, please call out if this is not the case. Bug: 236704164 Bug: 229362273 Test: TH passes Change-Id: I55f4cbf3824b988a164fb7087e99007f3d551833
This commit is contained in:
@@ -83,7 +83,9 @@ public class AccessoryChat extends Activity implements Runnable, TextView.OnEdit
|
||||
super.onCreate(savedInstanceState);
|
||||
|
||||
mUsbManager = (UsbManager) getSystemService(Context.USB_SERVICE);
|
||||
mPermissionIntent = PendingIntent.getBroadcast(this, 0, new Intent(ACTION_USB_PERMISSION), PendingIntent.FLAG_MUTABLE_UNAUDITED);
|
||||
mPermissionIntent = PendingIntent.getBroadcast(this, 0,
|
||||
new Intent(ACTION_USB_PERMISSION).setPackage(this.getPackageName()),
|
||||
PendingIntent.FLAG_MUTABLE);
|
||||
IntentFilter filter = new IntentFilter(ACTION_USB_PERMISSION);
|
||||
registerReceiver(mUsbReceiver, filter);
|
||||
|
||||
|
||||
@@ -89,6 +89,7 @@ public class MainActivity extends Activity {
|
||||
for (int i = 0; i < mIdsToRollback.size(); i++) {
|
||||
Intent intent = new Intent(ACTION_NAME);
|
||||
intent.putExtra(ROLLBACK_ID_EXTRA, mIdsToRollback.get(i));
|
||||
intent.setPackage(getApplicationContext().getPackageName());
|
||||
PendingIntent pendingIntent = PendingIntent.getBroadcast(
|
||||
getApplicationContext(), 0, intent, FLAG_MUTABLE);
|
||||
mRollbackManager.commitRollback(mIdsToRollback.get(i),
|
||||
|
||||
Reference in New Issue
Block a user