Loading HuntDB...

Theft of arbitrary files in LINE Lite client for Android

Medium
L
LY Corporation
Submitted None

Team Summary

Official summary from LY Corporation

Due to one of the exported activities(com.linecorp.linelite.ui.android.share.SelectShareActivity) of LINE Lite client for Android before 2.17.0 not verifying the URI sent by a third-party application installed on the user device, the application with some interaction of the user would be able to retrieve private files within the LINE Lite client for Android to be copied to the publicly accessible directory.

Reported by hulkvision_

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic