Fix intent redirect bypass via selector in addCreatorToken
When evaluating whether to append a creator token to an intent in
ActivityManagerService.addCreatorToken, the system calculates a
targetPackage to determine if isCreatorSameAsTarget is true. If
the creator and target match, the token is omitted since the intent
is seemingly staying within the same application.
However, the previous logic failed to inspect the intent's selector.
An attacker could bypass the token injection by setting the outer
intent's package to their own app (tricking isCreatorSameAsTarget
into evaluating as true), while embedding a selector that explicitly
targets a victim's component. The Android routing framework
(ComputerEngine) evaluates the selector's explicit component and
routes the intent to the victim, successfully delivering the payload
without a creator token attached.
This change fixes the targetPackage calculation to correctly account
for selectors. It now prioritizes the explicit component of the outer
intent, followed by the explicit component or package of the selector,
and finally falls back to the outer intent's package constraint.
Bug: 487147249
Test: Manually verifies the PoC of the vulnerability no longer works
Flag: EXEMPT BUGFIX
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:dc03f183688231c065ac0e13ef10a00732ba7199
Cherrypick-From: https://googleplex-android-review.googlesource.com/q/commit:acbde95f3eec1695d5bf4fa52e4153ef1d1a708a
Merged-In: Idf5bdc7a5f9d1ca64b5504edc776685fd3bd3306
Change-Id: Idf5bdc7a5f9d1ca64b5504edc776685fd3bd3306
1 file changed