Posted by Lord Tuskington on Oct 19
I disagree with Nick Kralevich’s response. An attacker who has the ability
to locally modify an XSL file should not be able to leverage this to
achieve code execution. This crosses a trust boundary.
As for why I didn’t report this to security () android com, when Google starts
paying corporate tax instead of dodging it, I will report issues privately.
Lord Tuskington
Chief Financial Taxdodger
Google
On Sun, Oct 19, 2014 at 7:28 PM,…