Can download files on Android app without permission
Low
Vulnerability Details
## Summary:
If the owner of a file - of type PDF, document, image or presentation - shares it with a user and disable download, the user can still download it using the Android app.
## Steps To Reproduce:
1. As user1, in the "Files" app, create a folder containing files of different formats (PDF, .odt, .png, .odp...)
2. Share the folder to user2 and uncheck "Allow download" (repeat this step twice as unchecking the box doesn't apply the first time)
3. As user2, in the Android app, open:
- a PDF: in the viewer click the top right menu, choose "Download as" and select "PDF document" or "PDF document as...". You receive a "Download completed" notification and can open and save the file on your phone.
- a .odp: same as above
- a .odt: same as above and you can also choose ".epub"
- an image (.png, .jpg): choose "Use the image as" and "Wallpaper". The file will be saved in internal memory - not easily accessible but still. You can also choose the image as Whatsapp profile picture or contact photo
**Screenshots: **
{F3060341}
**Additional notes on the tests: **
- What I could open but couldn't download: .mp3, .mp4, .txt
- What I couldn't open because it won't load (there's an infinite loader and a "Loading takes longer than expected" error ): .md, .csv
- Trying to export the document by clicking "File">"Save as" from the viewer (pdf /odt) will open a pop up to choose a filename, and after clicking "Save" there's an infinite loading icon which is blocking the UI.
## Impact
Sensitive documents leak.
Actions
View on HackerOneReport Stats
- Report ID: 2380133
- State: Closed
- Substate: resolved
- Upvotes: 37