Theft of arbitrary files in LINE Lite client for Android
Medium
L
LY Corporation
Submitted None
Team Summary
Official summary from LY Corporation
Due to one of the exported activities(com.linecorp.linelite.ui.android.share.SelectShareActivity) of LINE Lite client for Android before 2.17.0 not verifying the URI sent by a third-party application installed on the user device, the application with some interaction of the user would be able to retrieve private files within the LINE Lite client for Android to be copied to the publicly accessible directory.
Actions:
Reported by
hulkvision_
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic