Android Intent URI permission manipulation

Returning a user-supplied Intent as a result

Description

Forwarding an externally supplied Intent while retaining URI permission flags such as FLAG_GRANT_READ_URI_PERMISSION or FLAG_GRANT_WRITE_URI_PERMISSION can let an attacker cause the app to delegate access to content URIs to another component.

Potential impact

  • Disclosure of app files or content URI data.
  • Data modification through delegated write access.
  • Bypass of permission boundaries.

Remediation

  1. Remove unnecessary grant flags before forwarding an external Intent.
  2. Validate the URI and destination component against an allow-list.
  3. Explicitly grant only the necessary permissions and revoke them after use.

Examples

Before

java
Intent result = getIntent();
result.putExtra("status", "ok");
setResult(RESULT_OK, result);
finish();

After

java
Intent result = new Intent();
result.putExtra("status", "ok");
setResult(RESULT_OK, result);
finish();

Explanation:

  • Before: Returning the original external Intent through setResult can let an attacker include URI permission flags and bypass the app's ContentProvider access restrictions.
  • After: Create a new Intent for setResult and copy only the required data.

References