Description
In showAvatarPicker of EditUserPhotoController.java, there is a possible cross user image leak due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Problem types
Information disclosure
Product status
15
References
android.googlesource.com/...cfc291977f33f14fba0bd2b7f7fe8f6c
android.googlesource.com/...462c6b0269a6e6035ce443ec29fd860e
source.android.com/security/bulletin/2025-04-01