Description
Forwarding an externally supplied Intent while retaining URI permission flags such as FLAG_GRANT_READ_URI_PERMISSION or FLAG_GRANT_WRITE_URI_PERMISSION can let an attacker cause the app to delegate access to content URIs to another component.
Potential impact
- Disclosure of app files or content URI data.
- Data modification through delegated write access.
- Bypass of permission boundaries.
Remediation
- Remove unnecessary grant flags before forwarding an external Intent.
- Validate the URI and destination component against an allow-list.
- Explicitly grant only the necessary permissions and revoke them after use.
Examples
Before
java
Intent result = getIntent();
result.putExtra("status", "ok");
setResult(RESULT_OK, result);
finish();
After
java
Intent result = new Intent();
result.putExtra("status", "ok");
setResult(RESULT_OK, result);
finish();
Explanation:
- Before: Returning the original external Intent through
setResultcan let an attacker include URI permission flags and bypass the app's ContentProvider access restrictions. - After: Create a new Intent for
setResultand copy only the required data.